Cybersecurity researchers have disclosed two denial-of-service (DoS) attack techniques, collectively named "CDN Tsunami," that exploit how major content delivery networks (CDNs) convert…
Alibaba Group's developer tools were targeted in a software supply chain attack via malicious npm packages impersonating private @ali-scoped packages. The attack…
The final-stage backdoor in the Alibaba supply chain attack injects malicious code into DingTalk, a popular enterprise collaboration app, to maintain persistence…
The backdoor used in the Alibaba supply chain attack targets Wukong, an enterprise collaboration application, by injecting malicious code to achieve persistence…
The backdoor used in the Alibaba supply chain attack targets Qoder, an enterprise collaboration application, by injecting malicious code to maintain persistence…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…
AlibabaAlibaba GroupbackdoorChinese-speaking threat actor
A sophisticated cross-platform remote access trojan (RAT) was delivered via malicious npm packages impersonating Alibaba's private packages. The RAT is capable of…