npm campaign profile: 18 malicious packages targeting Alibaba tools ecosystem

A new npm supply chain campaign shows that attackers are no longer just spreading generic malware to chase large download counts. According to The Hacker News and Socket technical reporting, 18 malicious npm packages were designed to imitate or track internal packages in Alibaba's tooling ecosystem, delivering a cross-platform RAT into Chinese-speaking developer environments.

Minh họa gói npm độc hại trong chiến dịch nhắm vào công cụ Alibaba

The campaign began with packages that looked harmless

A prominent case is the package lib-mtop, an unscoped package whose name resembles a private package under the @ali. The package had been published since November 2023 with almost no meaningful functionality, before three new versions were pushed in March and April 2026. Socket has not concluded whether this was a maintainer account takeover or intentional developer activity, but the new changes added a loader capable of downloading remote JavaScript via curl and executing it on the victim machine.

The maintainer account ch4ce was also associated with the packages aone-kit, aone-kit-cli, aone-sandbox and local-config-parser. The first three packages acted as covers, using names similar to private packages in the @ali. Separately, local-config-parser has a legitimate function for parsing JSON configuration, but within the full dependency tree it becomes one link in the malware deployment chain.

How the attack abuses trust in development environments

The danger of the campaign lies in how the malware is split across multiple packages. Upper-layer packages serve only as lures, while the intermediate package smart-config-manager pulls in components such as cloud-config-fetcher and local-config-parser. Viewed individually, some components may look legitimate or only mildly suspicious; installed together, they form a mechanism for loading configuration, escaping the sandbox and calling the next payload.

Socket says the package cloud-config-fetcher downloads a configuration file from an attacker-controlled GitHub repository and saves it as .cloud-preferences.json. Then the rule-evaluation logic in local-config-parser uses Node.js's vm module to run expressions. The malware abuses a sandbox escape technique through the constructor of the input object to gain access to process, then invokes the module loader and downloads payloads from infrastructure hosted on Alibaba Cloud to blend in with legitimate traffic.

The final payload can persist and move laterally

At a later stage, the malware identifies the operating system and chooses its deployment path. On Windows, it can terminate security applications, VPNs and the Alilang office tool, then replace core components with trojanized versions. On Linux, the payload is downloaded to /tmp, launched as a detached process and deleted from disk after loading. On macOS, the malware injects a background script into ~/.zshrc and configures a Launch Agent to run every 10 minutes.

The final payload is described as a cross-platform RAT with command execution, file upload and download, host information collection, payload staging, encrypted TCP proxying and lateral movement capabilities. Notably, it can inject code into enterprise collaboration tools such as DingTalk, Wukong and Qoder, which are more common in Chinese-speaking environments.

Signs point to industrial espionage as the objective

The campaign does not target high download counts; it targets environments likely to have access to the impersonated private packages. Package names tied to Aone, Alibaba Group's internal R&D infrastructure system, further support the assessment that the operators wanted access to software development systems, technical documentation and internal processes rather than broad malware distribution.

Socket observed that later-stage source code contained many Chinese-language comments, while GitHub commits used the UTC+08:00 time zone. This is not definitive attribution evidence, but it fits the hypothesis of a Chinese-speaking actor targeting Chinese-speaking developers. Researcher Karlo Zanki assessed that the campaign's objective appears to be industrial espionage, with impact that is difficult to measure because of the targeting and lateral movement potential.

Packages that should be reviewed immediately

The list cited by The Hacker News and Socket includes lib-mtop, aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, cloud-config-fetcher, fast-transform-pipeline, aone-cloud-cli, colder-cli, def-open-client, feedback-ai-sdk, flight-compare-analyzer, lwp-web-client, lzd-unified-station-sdk, open-worker-cli, test-skill-zip and uniapi-bridge.

Organizations that installed any of these packages should treat the related environment as potentially compromised. Response should be performed from a clean machine and include revoking and rotating tokens, SSH keys, cloud access keys, npm keys and CI/CD secrets; reviewing package installation history; checking shell configuration files, Launch Agents, suspicious processes, outbound connections and signs of code injection in internal collaboration tools.

Lessons for software supply chain governance

The case shows that reviewing packages one by one is not enough. A package may have a reasonable description, real functionality and relatively clean initial behavior, but when combined with other dependencies it can form a malicious execution chain. Enterprises should tightly control package sources, enable lockfiles, use registry proxies with blocking policies, separate build environments, monitor post-install behavior and limit developer machine privileges to critical internal systems.

For development teams, the key principle is not to treat developer workstations as an absolute trust zone. When a dev machine has access to source code, CI/CD, artifact repositories and collaboration tools, one malicious package can become the starting point for data leakage, pipeline compromise and deeper intrusion into the organization.

VNCyberS compiled by VNCyberS from The Hacker News and Socket

Contact Us

Email: [email protected]
Phone: +84 903260277