18 Malicious npm Packages Target Alibaba Tool Users

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Socket researchers uncovered 18 malicious npm packages targeting Alibaba developer tools with a cross-platform RAT as part of a software supply chain attack aimed at Chinese-speaking environments.
- The unscoped package "lib-mtop" — impersonating a private @ali-scoped package — sat dormant since November 2023 before malicious versions v1.0.1 through v1.0.3 were pushed in March and April, loading a remote JavaScript payload via curl.
- The malicious loader logic is fragmented across multiple packages in the same dependency tree, with at least 10 top-layer lure packages routing through "smart-config-manager" as a middle-layer bridge to the packages containing the actual loader.
- The OS-specific payload — delivered via a rule engine using Node's vm module — terminates and trojanizes Alilang enterprise security on Windows, drops a binary to /tmp on Linux, and injects a malicious script into ~/.zshrc plus a 10-minute Launch Agent on macOS.
- The full backdoor supports command execution, file upload/download, host reconnaissance, and lateral movement, persisting by injecting code into enterprise collaboration apps DingTalk, Wukong, and Qoder, with payload download hosted on a domain masquerading as Alibaba ("aone-cli-next.oss-cn-beijing.aliyuncs[.]com").
- Socket researcher Karlo Zanki assessed the campaign as likely industrial espionage, noting that while download numbers for the malicious packages are low, the targeted nature and lateral-spread capabilities make the actual impact difficult to evaluate.
Why it matters: Any organization in the Alibaba developer ecosystem faces material risk of IP and credential compromise through this campaign's lateral movement and enterprise app injection — even though download numbers for the malicious packages remain low, the target specificity means the impact per victim could be severe.




