18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

2026-08-04T01:24:00Z4b508a0a5c5a15a4de0ef9385de55050377dcbcea9609b6d42a4c4d6546cc024
CVE-2026-17583CVE-2026-18577CVE-2026-484495G-securityAI-securityAdobe-Campaign-ClassicAndroidAzure-Cosmos-DBN-ableSonicWallVPNactive-exploitationarbitrary-code-executioncloud-securitycredential-theftcryptocurrency-theftdata-breachiOSidentity-attacksmacOSmalwarenpmpasskeysphishingransomwareremote-access-trojansoftware-supply-chain

What happened

The document is a cybersecurity news feed covering active exploitation, malware campaigns, supply-chain compromises, ransomware, cloud and identity attacks, and critical vulnerabilities. The highest-risk items include attacks against SonicWall SMA 1000, N-able N-central, Adobe Campaign Classic, Azure Cosmos DB, Google Password Manager passkeys, and malicious npm packages delivering cross-platform RATs. Several entries describe confirmed exploitation, data theft, arbitrary code execution, session hijacking, or large-scale financial loss.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4b508a0a5c5a15a4de0ef9385de55050377dcbcea9609b6d42a4c4d6546cc024
Enrichment time
2026-08-04T01:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.