18 npm packages split a cross-platform RAT loader across a shared dependency chain to target developers inside Alibaba Group
Socket traced a three-month-old, still-live campaign in which no single npm package looks malicious on its own — the loader logic is split across a lure package, a middle-layer dependency, and a "rule engine" package that uses a classic Node.js `vm` sandbox escape (`items.constructor.constructor` → `Function` → `process`) to fetch and run a remote payload. The final stage, `aone-cli`, is a targeted RAT with DingTalk-based lateral movement aimed squarely at Alibaba's internal Aone tooling; commits are timestamped UTC+0800 and the C2 infrastructure has stayed live undetected for three months. If your org or contractors touch @ali-scoped packages, treat any environment that installed `lib-mtop`, `smart-config-manager`, `aone-kit`, or the other 15 IOC'd packages as compromised and rotate npm/GitHub/cloud secrets from a clean machine, not the infected host.