Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers

Blog post from Socket

Post Details
Company
Date Published
Author
Karlo Zanki
Word Count
2,202
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

In a sophisticated cyber campaign, unknown threat actors spread a malicious downloader across multiple npm packages to target users of Alibaba tools, specifically through the covert deployment of a Remote Access Trojan (RAT) capable of data exfiltration and command execution. The campaign involved the takeover or rogue alteration of an npm package called lib-mtop, imitating private packages from the @ali scope, which is associated with Alibaba's internal tools. The malware, distributed via a dependency tree that includes seemingly benign packages like local-config-parser and cloud-config-fetcher, employs a classic loader mechanism to download and execute malicious payloads from attacker-controlled servers, leveraging Node.js sandbox escape techniques to bypass security. The final payload, a sophisticated RAT, employs various persistence methods and targets developers within Alibaba Group for industrial espionage, with all infrastructure elements remaining active months after the campaign's launch. The campaign's execution, from the use of npm packages mimicking Alibaba's internal tools to the targeted RAT deployment, suggests a high level of sophistication and focus on Chinese-speaking developers.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 2,479 445 126 -1%
Kubernetes 1 2,471 342 109 +14%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.