18 Malicious npm Packages Impersonate Alibaba Tools: Hunting a Cross-Platform RAT

18 malicious npm packages mimic Alibaba tools to drop a cross-platform RAT. Learn how this dependency confusion attack threatens developers via OS-specific payloads.

18 Malicious npm Packages Impersonate Alibaba Tools: Hunting a Cross-Platform RAT
Malware

Illustrative image generated with AI

On August 3, 2026, a security analysis uncovered eighteen npm packages designed to target developers working with the Alibaba ecosystem. Published by the account “ch4ce,” these modules deliver a remote access trojan (RAT) capable of operating on Windows, Linux, and macOS. The attack exploits dependency confusion techniques and a multi-stage infrastructure, with a domain impersonating a legitimate Alibaba Cloud endpoint. Although the public download count appears low, the campaign is highly targeted, and the RAT enables lateral movement through applications such as DingTalk and Qoder.

Discovery and the Full Package List

The “ch4ce” account uploaded the malicious packages at different times. The longest-lived, lib-mtop, appeared in an empty version as early as November 2023; the active variants (v1.0.1–1.0.3) arrived between March and April 2026. The chosen names – aone-kit, aone-kit-cli, aone-sandbox, aone-cloud-cli and others – mimic private packages that in the npm registry use the @ali scope, reserved for internal Alibaba Group tools. In environments configured to resolve dependencies from that namespace, the trap is automatic: the package manager first checks the public registry, finds a package with the same name, and installs it without warnings.

The complete list of affected modules is:
lib-mtop, aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, cloud-config-fetcher, fast-transform-pipeline, aone-cloud-cli, colder-cli, def-open-client, feedback-ai-sdk, flight-compare-analyzer, lwp-web-client, lzd-unified-station-sdk, open-worker-cli, test-skill-zip, uniapi-bridge.

A Multi-Stage Attack with Rules Fetched from GitHub

The malicious logic does not reside in a single file. The surface packages call smart-config-manager, a bridge module that in turn depends on lower-level components containing the loader. One of these retrieves a “rule engine” configuration from a public GitHub repository. The engine abuses Node.js’s vm module to interpret the rules and, depending on the detected operating system, downloads an additional payload.

The staging domain is aone-cli-next.oss-cn-beijing.aliyuncs[.]com, crafted to resemble an Alibaba Cloud Object Storage Service endpoint (Beijing region). The final payload acts differently on each platform.

Final Payload: Trojanized Alilang, Launch Agent Every 10 Minutes

On Windows the RAT locates and terminates the enterprise security application Alilang, then replaces it with a tampered version. On Linux it downloads a binary into /tmp, runs it as a detached process, and deletes it immediately after loading it in memory. On macOS it inserts a malicious script into ~/.zshrc and registers a Launch Agent that reactivates every 10 minutes, ensuring persistence even after reboots.

Once active, the RAT provides command execution, file upload and download, system reconnaissance, staging of additional tools, and lateral movement. To spread across machines it injects into widely used collaboration applications in China such as DingTalk, Wukong, and Qoder. The code contains comments in Chinese, and commits were made in the UTC+08:00 time zone, clues that point to a Chinese-speaking actor. The most likely objective is industrial espionage, aiming to steal intellectual property and access development networks.

Countermeasures and the Parallel Attack on PyPI

Anyone developing with Alibaba tools must immediately check whether any of the 18 packages are present in their npm environments. If found, the environment should be considered compromised. All credentials and secrets must be rotated from a clean machine; systems should be analyzed for suspicious Launch Agents, modifications to .zshrc, abnormal processes, and altered versions of Alilang. It is advisable to isolate build environments and restrict access to private registries with scopes limited to authorized networks only.

During the same period, an unidentified actor also struck PyPI. They compromised the GitHub account of the maintainer of the quantum library mrmustard (developed by Xanadu) through self-hosted CI runners, stealing publishing secrets. The poisoned version 0.7.4 installs three persistence mechanisms and steals SSH private keys, AWS credentials, Kubernetes configurations, and HPC queue information (SLURM, GPU inventories), exfiltrating everything to metrics.femboy[.]energy. This incident confirms that the entire open-source software supply chain – npm, PyPI, and developer accounts – is under pressure from adversaries with long-term goals.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →