Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
Blog post from Socket
In a sophisticated cyber campaign, unknown threat actors spread a malicious downloader across multiple npm packages to target users of Alibaba tools, specifically through the covert deployment of a Remote Access Trojan (RAT) capable of data exfiltration and command execution. The campaign involved the takeover or rogue alteration of an npm package called lib-mtop, imitating private packages from the @ali scope, which is associated with Alibaba's internal tools. The malware, distributed via a dependency tree that includes seemingly benign packages like local-config-parser and cloud-config-fetcher, employs a classic loader mechanism to download and execute malicious payloads from attacker-controlled servers, leveraging Node.js sandbox escape techniques to bypass security. The final payload, a sophisticated RAT, employs various persistence methods and targets developers within Alibaba Group for industrial espionage, with all infrastructure elements remaining active months after the campaign's launch. The campaign's execution, from the use of npm packages mimicking Alibaba's internal tools to the targeted RAT deployment, suggests a high level of sophistication and focus on Chinese-speaking developers.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 2 | 2,479 | 445 | 126 | -1% |
| Kubernetes | 1 | 2,471 | 342 | 109 | +14% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.