securityonline.info 3 Aug 2026, 08:03 UTC

Malicious npm Packages Hit Alibaba Devs with Spyware RAT

Malicious npm Packages Hit Alibaba Devs with Spyware RAT
CyberSIXT Evidence Panel Source marked as original reporting

THE article discusses a recent npm supply chain attack targeting Alibaba developers, specifically those from Taobao, Tmall, and Alibaba Cloud. The attack involves a cross-platform RAT (Remote Access Trojan) that is delivered through malicious npm packages imitating Alibaba's internal packages. The malware is designed to execute commands, transfer files, and conduct reconnaissance while maintaining a low profile by spreading its loader across multiple innocuous modules.

The final payload, named 'aone-cli', establishes a command-and-control connection for espionage purposes. The article outlines how to detect and respond to such attacks to safeguard against future threats.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline