Distributed npm Packages Deliver Cross-Platform RAT Targeting Alibaba Developers

· Original article ↗

Summary

Researchers uncovered a targeted campaign that spreads malicious functionality across npm packages impersonating Alibaba’s private packages. The chain delivers a cross-platform RAT with data theft, command execution, persistence, and lateral-movement capabilities.

Key points

  • Unknown actors distributed the campaign through linked npm packages, including lures impersonating private packages in Alibaba’s @ali scope; the activity remained undetected for about three months.
  • A malicious configuration chain uses a Node.js vm sandbox escape to access the host process and download further stages from attacker-controlled GitHub and Alibaba Cloud infrastructure.
  • The final aone-cli payload is a cross-platform RAT supporting command execution, file transfer, reconnaissance, an encrypted reverse TCP proxy, and DingTalk-based lateral movement.
  • Persistence varies by platform: the malware modifies shell startup files and installs a Launch Agent on macOS, replaces security-app code on Windows, and runs a detached payload on Linux.
  • The campaign also injects code into Python scripts used by tools including DingTalk, Wukong, and Qoder; the researchers assess industrial espionage as a possible goal but say the impact is unknown.
  • Teams that installed affected packages should treat those systems as compromised, investigate from clean machines, preserve evidence, remove the packages, rotate exposed secrets, and check for the listed indicators.

Article Details

Attack Vectors
  • Malicious unscoped npm packages imitate private @ali-scoped packages and pull in a dependency chain that delivers downloader functionality.
  • cloud-config-fetcher retrieves attacker-controlled configuration from GitHub; local-config-parser evaluates a malicious rule in that configuration.
  • The malicious rule escapes the Node.js vm sandbox, accesses the host process and module loader, and downloads a further payload.
  • Later stages deploy a cross-platform RAT and establish persistence through shell configuration, a Launch Agent, replacement of Alilang application code, or injection into Python scripts used by enterprise collaboration tools.
Defensive Notes
  • Treat environments that installed affected packages as potentially compromised. Preserve forensic artifacts where possible, identify affected developer machines, and remove the packages.
  • Rotate secrets exposed to affected environments from a clean machine, not the potentially infected host.
  • Audit Python files for # __INJECT_MARKER__ and check for a ROBOT_UID environment variable set to 3201d407b7899a12d6d439950511c6a5.
  • Review traffic to the reported C2 infrastructure, including requests with Origin and Referer set to https://alidocs.dingtalk.com, and investigate suspicious DingTalk activity or lateral movement.

Indicators of compromise

TypeIndicatorContext
DOMAINxemzqli2vu[.]ai-app[.]pubPrimary C2 domain.
HOSTNAMEdiamond-cli-znsxphqell[.]cn-shanghai[.]fcapp[.]runReverse-proxy WebSocket C2 host.
SHA2560910ecfa049738ef3f2540855341a380df89224ff71da94b4c21689fd66f62e3Hash of aone-cli.js deployed on macOS.
SHA25633b58598eb317553942e27545982d4c25ce6120eae10e42393746eb0e02ecae9Hash of aone-kit-update deployed on Linux from lib-mtop.
SHA25641957bd0ba2d9c07af2e069f10780fdf6b2102c065bebe0db2136dfe07d67a28Hash of the crypto.js loader associated with lib-mtop.
SHA2566044974c633b3a319c31bb32110411520c425e89722a64806528553227e7a50aHash of the third-stage setting.js loader.
SHA25684a6ccaaab1596139d28e822f40cc99c68d337d4c81d1c6d9692c1d6bb22e4afHash of the preferences.json configuration containing malicious rules.
SHA256b8b81af76163bdcc5b4f7d8fe6795f164991f8a62678c971db031b9e90a27813Hash of aone-cli deployed on Linux.
SHA256e5d8350f1540fe91145dc262c455bca7748ad97dafb2d9facd5adebed9f66d2dHash of aone-cli-deps.tar.gz containing an older aone-cli.js.
SHA256ef9a1896eeaae929800eade768276e2240ef252d26d0d96c1950a1a5e1aadb34Hash of aone-cli.zip deployed on Windows.
URLhxxps[:]//aone-ai-cli[.]oss-cn-beijing[.]aliyuncs[.]com/app/release/aone-cliIdentified malicious aone-cli payload-delivery URL.
URLhxxps[:]//aone-ai-cli[.]oss-cn-beijing[.]aliyuncs[.]com/app/release/aone-cli-deps[.]tar[.]gzIdentified malicious aone-cli-deps.tar.gz payload-delivery URL.
URLhxxps[:]//aone-ai-cli[.]oss-cn-beijing[.]aliyuncs[.]com/app/release/aone-cli[.]jsIdentified malicious aone-cli.js payload-delivery URL.
URLhxxps[:]//aone-ai-cli[.]oss-cn-beijing[.]aliyuncs[.]com/app/release/aone-cli[.]zipIdentified malicious aone-cli.zip payload-delivery URL.
URLhxxps[:]//aone-cli-next[.]oss-cn-beijing[.]aliyuncs[.]com/config/setting[.]jsPayload-delivery URL for the third-stage setting.js loader.
URLhxxps[:]//aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/aone-kit-update/aone-kit-updateIdentified malicious aone-kit-update payload-delivery URL.
URLhxxps[:]//aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/aone-kit-update/aone-kit[.]jsIdentified malicious aone-kit.js payload-delivery URL.
URLhxxps[:]//aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/aone-kit-update/app[.]asarIdentified malicious app.asar payload-delivery URL.
URLhxxps[:]//aone-kit[.]oss-cn-beijing[.]aliyuncs[.]com/plugins/crypto[.]jsIdentified malicious crypto.js payload-delivery URL.
URLhxxps[:]//raw[.]githubusercontent[.]com/smi1e2u/smart-config-manager/main/defaults/preferences[.]jsonAttacker-controlled GitHub configuration resource containing the malicious rule.

MITRE ATT&CK

Malware

Vendors

Products

Related Articles