A sophisticated supply chain attack targeting Alibaba Group developers was discovered on npm, remaining undetected for over 3 months. Threat actors published 15 malicious packages that impersonate private @ali-scoped Alibaba packages, distributing malicious loader functionality across a dependency chain. Individual packages appear benign in isolation but combine to download and execute a cross-platform Remote Access Trojan (RAT). The attack uses a Node.js vm sandbox escape technique to bypass security boundaries, then deploys platform-specific persistence mechanisms on macOS, Windows, and Linux. The final RAT payload supports command execution, file transfer, host reconnaissance, encrypted reverse TCP proxy, and lateral movement via DingTalk enterprise tools. C2 traffic is camouflaged with fake DingTalk headers, and code comments in Chinese suggest a Chinese-speaking threat actor conducting industrial espionage. Affected teams should treat compromised environments as fully breached and rotate all secrets from a clean machine.