securityonline.info 8/3/2026, 9:46:30 AM · external

Malicious npm Packages Hit Alibaba Devs with Spyware RAT

Malicious npm Packages Hit Alibaba Devs with Spyware RAT
CyberSIXT Evidence Panel Source marked as original reporting

THE article discusses a recent npm supply chain attack targeting Alibaba developers, specifically those from Taobao, Tmall, and Alibaba Cloud. The attack involves a cross-platform RAT (Remote Access Trojan) that is delivered through malicious npm packages imitating Alibaba's internal packages. The malware is designed to execute commands, transfer files, and conduct reconnaissance while maintaining a low profile by spreading its loader across multiple innocuous modules.

The final payload, named 'aone-cli', establishes a command-and-control connection for espionage purposes. The article outlines how to detect and respond to such attacks to safeguard against future threats.

View full article

Article by CyberSIXT