**Source : The Hacker News | 4 août 2026** Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package 👉 **Lire l'article complet sur The Hacker News :** [https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html](https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html)