Distributed npm Packages Deliver Cross-Platform RAT Targeting Alibaba Developers

Summary
Researchers uncovered a targeted campaign that spreads malicious functionality across npm packages impersonating Alibaba’s private packages. The chain delivers a cross-platform RAT with data theft, command execution, persistence, and lateral-movement capabilities.
Key points
- Unknown actors distributed the campaign through linked npm packages, including lures impersonating private packages in Alibaba’s @ali scope; the activity remained undetected for about three months.
- A malicious configuration chain uses a Node.js vm sandbox escape to access the host process and download further stages from attacker-controlled GitHub and Alibaba Cloud infrastructure.
- The final aone-cli payload is a cross-platform RAT supporting command execution, file transfer, reconnaissance, an encrypted reverse TCP proxy, and DingTalk-based lateral movement.
- Persistence varies by platform: the malware modifies shell startup files and installs a Launch Agent on macOS, replaces security-app code on Windows, and runs a detached payload on Linux.
- The campaign also injects code into Python scripts used by tools including DingTalk, Wukong, and Qoder; the researchers assess industrial espionage as a possible goal but say the impact is unknown.
- Teams that installed affected packages should treat those systems as compromised, investigate from clean machines, preserve evidence, remove the packages, rotate exposed secrets, and check for the listed indicators.
Article Details
- Attack Vectors
- Malicious unscoped npm packages imitate private @ali-scoped packages and pull in a dependency chain that delivers downloader functionality.
- cloud-config-fetcher retrieves attacker-controlled configuration from GitHub; local-config-parser evaluates a malicious rule in that configuration.
- The malicious rule escapes the Node.js vm sandbox, accesses the host process and module loader, and downloads a further payload.
- Later stages deploy a cross-platform RAT and establish persistence through shell configuration, a Launch Agent, replacement of Alilang application code, or injection into Python scripts used by enterprise collaboration tools.
- Defensive Notes
- Treat environments that installed affected packages as potentially compromised. Preserve forensic artifacts where possible, identify affected developer machines, and remove the packages.
- Rotate secrets exposed to affected environments from a clean machine, not the potentially infected host.
- Audit Python files for # __INJECT_MARKER__ and check for a ROBOT_UID environment variable set to 3201d407b7899a12d6d439950511c6a5.
- Review traffic to the reported C2 infrastructure, including requests with Origin and Referer set to https://alidocs.dingtalk.com, and investigate suspicious DingTalk activity or lateral movement.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | xemzqli2vu[.]ai-app[.]pub | Primary C2 domain. |
| HOSTNAME | diamond-cli-znsxphqell[.]cn-shanghai[.]fcapp[.]run | Reverse-proxy WebSocket C2 host. |
| SHA256 | 0910ecfa049738ef3f2540855341a380df89224ff71da94b4c21689fd66f62e3 | Hash of aone-cli.js deployed on macOS. |
| SHA256 | 33b58598eb317553942e27545982d4c25ce6120eae10e42393746eb0e02ecae9 | Hash of aone-kit-update deployed on Linux from lib-mtop. |
| SHA256 | 41957bd0ba2d9c07af2e069f10780fdf6b2102c065bebe0db2136dfe07d67a28 | Hash of the crypto.js loader associated with lib-mtop. |
| SHA256 | 6044974c633b3a319c31bb32110411520c425e89722a64806528553227e7a50a | Hash of the third-stage setting.js loader. |
| SHA256 | 84a6ccaaab1596139d28e822f40cc99c68d337d4c81d1c6d9692c1d6bb22e4af | Hash of the preferences.json configuration containing malicious rules. |
| SHA256 | b8b81af76163bdcc5b4f7d8fe6795f164991f8a62678c971db031b9e90a27813 | Hash of aone-cli deployed on Linux. |
| SHA256 | e5d8350f1540fe91145dc262c455bca7748ad97dafb2d9facd5adebed9f66d2d | Hash of aone-cli-deps.tar.gz containing an older aone-cli.js. |
| SHA256 | ef9a1896eeaae929800eade768276e2240ef252d26d0d96c1950a1a5e1aadb34 | Hash of aone-cli.zip deployed on Windows. |
| URL | hxxps[:]//aone-ai-cli[.]oss-cn-beijing[.]aliyuncs[.]com/app/release/aone-cli | Identified malicious aone-cli payload-delivery URL. |
| URL | hxxps[:]//aone-ai-cli[.]oss-cn-beijing[.]aliyuncs[.]com/app/release/aone-cli-deps[.]tar[.]gz | Identified malicious aone-cli-deps.tar.gz payload-delivery URL. |
| URL | hxxps[:]//aone-ai-cli[.]oss-cn-beijing[.]aliyuncs[.]com/app/release/aone-cli[.]js | Identified malicious aone-cli.js payload-delivery URL. |
| URL | hxxps[:]//aone-ai-cli[.]oss-cn-beijing[.]aliyuncs[.]com/app/release/aone-cli[.]zip | Identified malicious aone-cli.zip payload-delivery URL. |
| URL | hxxps[:]//aone-cli-next[.]oss-cn-beijing[.]aliyuncs[.]com/config/setting[.]js | Payload-delivery URL for the third-stage setting.js loader. |
| URL | hxxps[:]//aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/aone-kit-update/aone-kit-update | Identified malicious aone-kit-update payload-delivery URL. |
| URL | hxxps[:]//aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/aone-kit-update/aone-kit[.]js | Identified malicious aone-kit.js payload-delivery URL. |
| URL | hxxps[:]//aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/aone-kit-update/app[.]asar | Identified malicious app.asar payload-delivery URL. |
| URL | hxxps[:]//aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto[.]js | Identified malicious crypto.js payload-delivery URL. |
| URL | hxxps[:]//raw[.]githubusercontent[.]com/smi1e2u/smart-config-manager/main/defaults/preferences[.]json | Attacker-controlled GitHub configuration resource containing the malicious rule. |
MITRE ATT&CK
T1059.007 · JavaScriptlocal-config-parser evaluates a malicious JavaScript rule that escapes its Node.js vm sandbox and executes downloader code.T1070.004 · File DeletionA later stage cleans up malicious artifacts downloaded during earlier infection stages.T1071.001 · Web ProtocolsThe RAT polls its C2 endpoint using HTTP requests with forged Origin and Referer headers resembling DingTalk page traffic.T1082 · System Information DiscoveryThe setting.js stage fingerprints the host platform before selecting a platform-specific payload.T1105 · Ingress Tool TransferThe dependency-chain loader and subsequent stages download malicious configuration and payloads from attacker-controlled locations.T1195.001 · Compromise Software Dependencies and Development ToolsMalicious npm packages enter developer environments through a dependency chain attached to packages imitating private @ali-scoped packages.T1543.001 · Launch AgentThe macOS stage sets up a Launch Agent to run at 10-minute intervals.T1546.004 · Unix Shell Configuration ModificationThe macOS stage inserts a malicious background script into ~/.zshrc.T1554 · Compromise Host Software BinaryThe Windows stage replaces the official Alilang application's app.asar with a Trojan copy.T1562.001 · Disable or Modify ToolsA later stage kills the official Alilang security app and silences logging mechanisms.
Malware
Vendors
Products
AlilangKills the official Alilang security app and replaces its core code (app.asar) with a Trojan copy.Aonedoesn’t use any novel or interesting techniques. The same maintainer account published 4 other packages, aone-kit, aone-kit-cli, aone-sandbox and ****local-config-parser . The first three are empty wrappers that haveDingTalkThe final payload is a covert and highly targeted RAT capable of data exfiltration, command execution and lateral spreading using DingTalk toolsGitHubregistered by Alibaba Group. Code references to packages from this scope can be found across several GitHub repositories. The @ali scope is used for hosting Alibaba's private packages used in internal projects andNode.jsit truly implements that logic. It parses rules from a local json config file and evaluates them using Node.js vm module for isolated expression evaluation. Nothing suspicious to observe, a regular package doingnpmUnknown threat actors distribute malicious downloader functionality separated across several npm packages targeting users of Alibaba tools.QoderC2 server. Targeted tools are typical of Chinese-speaking environment and include DingTalk, Wukong and Qoder enterprise collaboration tools.Wukongfrom the C2 server. Targeted tools are typical of Chinese-speaking environment and include DingTalk, Wukong and Qoder enterprise collaboration tools.