Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
ID: 1adfa10b-8571-52b4-85a9-4a3b0646e499
STIX ID: report--1adfa10b-8571-52b4-85a9-4a3b0646e499
Feed Name: Socket Blog
Unknown actors published malicious npm packages impersonating Alibaba's private `@ali` packages to deliver a multi-stage loader that fetches and executes staged payloads from attacker-controlled GitHub and OSS hosts, culminating in a targeted cross-platform Remote Access Trojan (aone-cli) capable of reconnaissance, data exfiltration, command execution, persistence (including AI-tool poisoning), and lateral movement via DingTalk; the report includes IoCs, C2 domains, hashes, and remediation guidance for affected developer environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
