Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    I’ve Waited 8 Years for Overwatch’s D.Mon. Her Gameplay Didn’t Disappoint

    August 7, 2026

    Our Favorite Fans Are on Sale to Help With Summer Heat Waves (2026)

    August 7, 2026

    What Chocolate Finance got right about S’pore’s changing savings habits

    August 7, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
    Cybersecurity

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    InfoForTechBy InfoForTechAugust 3, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.

    One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package under the “@ali” scope. Although the npm package was first published sometime in November 2023 with no functionality, three new versions (v1.0.1, v1.0.2, and v1.0.3) were uploaded earlier this March and April.

    It’s currently not clear if this was the result of a maintainer account takeover or the project developer opting to go rogue. Regardless of how the malicious changes were pushed, the newly added changes feature a loader that’s designed to fetch a remote JavaScript payload using curl and then execute it.

    The same maintainer account “ch4ce,” which currently redirects to a “not found” error on npmjs[.]com, has also published four other packages: aone-kit, aone-kit-cli, aone-sandbox, and local-config-parser.

    “The first three are empty wrappers that have the same name as private, @ali-scoped packages which they declare as a dependency in the package.json file,” Socket security researcher Karlo Zanki said in an analysis.

    The last package, local-config-parser, implements a legitimate JSON configuration file parser, but features dependencies that, on their own, are innocuous and are published from other npm user accounts. When combined together, they serve as a conduit for an advanced RAT targeting developers who are likely working in companies that are part of the Alibaba Group.

    Specifically, the malicious loader functionality is split and embedded into several packages delivered to the targets as part of the same dependency tree. The top-layer packages, which impersonate private packages from the @ali scope, serve as decoys that activate the installation of the dependency tree.

    “When such a package is installed in an environment that has access to impersonated, scoped private packages, the dependency resolution works as expected, with a little extra functionality delivered through additional dependencies that get installed,” Socket explained.

    As many as 10 top-layer lure packages have been found to depend on “smart-config-manager,” which functions akin to a middle-layer bridge that connects them to the malicious packages containing the loader logic. One of the low-layer packages proceeds to contact a GitHub repository to retrieve and store a rule engine configuration, and then it uses it to execute a malicious payload that then contacts a remote server to fetch secondary malware.

    What’s notable about the attack is that the rule engine makes use of the vm module to implement the final phase and perform the payload download depending on the victim’s operating system. The payload is retrieved from a domain that masquerades as Alibaba (“aone-cli-next.oss-cn-beijing.aliyuncs[.]com”) to blend in and sidestep detection.

    This stage performs a number of actions –

    • On Windows, it terminates the Alilang enterprise security, VPN, and office productivity app and replaces its core code with a trojanized version.
    • On Linux, it downloads a binary payload to /tmp, runs it as a detached process, and deletes the file from disk after it’s loaded into memory.
    • On macOS, it inserts a malicious background script into ~/.zshrc and sets up a 10-minute Launch Agent.

    The final payload is a complex backdoor equipped with comprehensive command execution, arbitrary file upload and download, host reconnaissance, payload staging, and lateral movement capabilities. It also has the capacity to persist by injecting malicious code into common enterprise collaboration applications like DingTalk, Wukong, and Qoder.

    Exactly who is behind the campaign is unknown, but the presence of Chinese language comments in the source code, combined with the fact that GitHub commits are timestamped with the UTC+08:00 offset, indicates that it’s possibly the work of a Chinese-speaking threat actor going after Chinese-speaking developers using tools belonging to Alibaba Group.

    “The goal of the campaign seems to be industrial espionage,” Zanki noted. “While the number of downloads for the malicious packages is not significant, the impact of the campaign is hard to evaluate, because of the targeted nature and lateral-spread capabilities of the final-stage payload.”

    The complete set of packages associated with the campaign is below –

    • lib-mtop
    • aone-kit
    • aone-kit-cli
    • aone-sandbox
    • local-config-parser
    • smart-config-manager
    • cloud-config-fetcher
    • fast-transform-pipeline
    • aone-cloud-cli
    • colder-cli
    • def-open-client
    • feedback-ai-sdk
    • flight-compare-analyzer
    • lwp-web-client
    • lzd-unified-station-sdk
    • open-worker-cli
    • test-skill-zip
    • uniapi-bridge

    Users who have installed any of the above packages should assume compromise, rotate sensitive credentials from a clean machine, and audit developer systems for signs of suspicious activity.

    The disclosure comes as unknown threat actors published a poisoned version of mrmustard (0.7.4), the photonic quantum computing Python library from Xanadu, to run an information stealer capable of harvesting SSH private keys, AWS credentials, and Kubernetes configurations, and exfiltrating them to an attacker server (“metrics.femboy[.]energy”).

    According to StepSecurity, the payload runs on every package import. Further analysis indicates that the primary maintainer’s GitHub account was breached to push the rogue version by probing the project’s self-hosted CI runners and exfiltrating its publishing secrets to a webhook[.]site URL.

    The malware “had three separate persistence mechanisms installed that keep a stealer running long after the package is uninstalled,” SafeDep said. “The credential theft targets research and HPC environments, collecting SLURM job queues and GPU inventories alongside the usual cloud secrets.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

    August 7, 2026

    ChatGPT Atlas Shuts Down Aug. 9: What Users Must Save Before Migrating

    August 7, 2026

    CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

    August 6, 2026

    Apple briefly removes Telegram from App Store over reported CSAM violation

    August 6, 2026

    Detect East-West Traffic Threats with Fidelis Network

    August 5, 2026

    Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

    August 5, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.