logo

Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers

ID: 1adfa10b-8571-52b4-85a9-4a3b0646e499

STIX ID: report--1adfa10b-8571-52b4-85a9-4a3b0646e499

Feed Name: Socket Blog

Threat Score
85/100

Date Published: 2026-07-28

Date Updated: 2026-07-29

Author: Karlo Zanki

...
...

Unknown actors published malicious npm packages impersonating Alibaba's private `@ali` packages to deliver a multi-stage loader that fetches and executes staged payloads from attacker-controlled GitHub and OSS hosts, culminating in a targeted cross-platform Remote Access Trojan (aone-cli) capable of reconnaissance, data exfiltration, command execution, persistence (including AI-tool poisoning), and lateral movement via DingTalk; the report includes IoCs, C2 domains, hashes, and remediation guidance for affected developer environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.