Skip to content

MALICIOUS (1) campaign cataloged at 2026-02-16(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-02-alibabacloude

Series of packages impersonating Alibaba Cloud. Two oldest hide code to run obfuscated code, but are likely to be used as dependency as the obfuscated code is not inside. The newest describe similar functionality, but the inside is highly obfuscated. Package names closely reassemble names of real Alibaba packages

Abuse categories

impersonation

Campaign uses impersonation.

obfuscation

Code uses obfuscation techniques to hide its true purpose.

typosquatting

The package name is an typosquatting variant of a popular package.

Packages in the campaign

campaign:2026-02-alibabacloude