A sophisticated supply chain attack targeting Alibaba Group developers was discovered on npm, remaining undetected for over 3 months. Threat actors published 15 malicious packages that impersonate private @ali-scoped Alibaba packages, distributing malicious loader functionality across a dependency chain. Individual packages appear benign in isolation but combine to download and execute a cross-platform Remote Access Trojan (RAT). The attack uses a Node.js vm sandbox escape technique to bypass security boundaries, then deploys platform-specific persistence mechanisms on macOS, Windows, and Linux. The final RAT payload supports command execution, file transfer, host reconnaissance, encrypted reverse TCP proxy, and lateral movement via DingTalk enterprise tools. C2 traffic is camouflaged with fake DingTalk headers, and code comments in Chinese suggest a Chinese-speaking threat actor conducting industrial espionage. Affected teams should treat compromised environments as fully breached and rotate all secrets from a clean machine.

11m read timeFrom socket.dev
Post cover image
Table of contents
Individual Non-Malicious Packages Combine Together to Provide Loader Functionality #Rule Engine Implements Virtual Machine to Construct Downloader #Final Payload - Targeted Remote Access Trojan #Defensive Guidance #Indicators of Compromise #
6 Impressions