18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
2026-08-04T07:23:59Z•d360c631b5482727fb3d05f5f72cec6dc804a5a836510672915d4e8a9d38bf4e
CVE-2026-17583CVE-2026-18577CVE-2026-48449AI-securityAndroidVPNactive-exploitationarbitrary-code-executionauthentication-bypasscloud-securitycredential-theftcryptocurrencycybersecuritydata-breachexploit-kitiOSmacOSmalvertisingmalwarenpmpasskeysphishingransomwareremote-access-trojansupply-chain-attacktelecomthreat-intelligence
What happened
The feed reports a broad set of cybersecurity incidents, including targeted software supply-chain compromises, malware and ransomware campaigns, authentication and passkey attacks, cloud and enterprise software vulnerabilities, telecom flaws, data breaches, phishing, malvertising, and AI-enabled offensive activity. Several items describe active exploitation or severe impact, including SonicWall and N-central compromises, arbitrary code execution in Adobe Campaign Classic, cloud database exposure, and large-scale cryptocurrency theft. Explicit CVEs include CVE-2026-17583, CVE-2026-18577, and CV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d360c631b5482727fb3d05f5f72cec6dc804a5a836510672915d4e8a9d38bf4e
- Enrichment time
- 2026-08-04T07:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.