Interestana
Home/News/18 Malicious npm Packages Deliver RAT to Alibaba Tool Users
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

18 Malicious npm Packages Deliver RAT to Alibaba Tool Users

18 Malicious npm Packages Deliver RAT to Alibaba Tool Users

Cybersecurity researchers have identified 18 malicious npm packages that deliver a cross-platform remote access trojan (RAT) to users of Alibaba developer tools. This discovery, detailed in a report by ReSecurity, points to a sophisticated, targeted software supply chain attack aimed at Chinese-speaking environments. The attack leverages the open-source package manager npm, a critical component for JavaScript development, to distribute malware. One of the identified malicious packages, "lib-mtop," bears the same name as a private Alibaba package, suggesting an attempt to impersonate legitimate software and trick developers into installing the compromised version. The RAT, once installed, can execute arbitrary commands on the victim's system, exfiltrate data, and potentially grant attackers persistent access.

The researchers from ReSecurity observed that these malicious packages were published between August 2023 and May 2024. The attack vector appears to be highly specific, focusing on developers who utilize Alibaba's internal development tools and are part of the Chinese-speaking software development community. The use of a RAT allows attackers to perform a wide range of malicious activities, including unauthorized access, data theft, and the deployment of further malware. The cross-platform nature of the RAT means it can infect systems running different operating systems, such as Windows, macOS, and Linux, significantly broadening its potential impact.

This incident highlights the persistent threat posed by software supply chain attacks, where attackers compromise legitimate software development pipelines or distribute malicious packages disguised as legitimate ones. The npm ecosystem, with its vast number of packages and frequent updates, is a particularly attractive target for such attacks. Developers often rely on third-party packages to accelerate development, and a single compromised dependency can have widespread consequences. The targeting of users of Alibaba's tools suggests a motive related to corporate espionage or the acquisition of sensitive information from within the Chinese tech sector.

ReSecurity's analysis indicates that the attackers are actively maintaining and updating their malicious packages, demonstrating a commitment to their campaign. The discovery of "lib-mtop" is particularly noteworthy, as it exploits the trust developers place in packages that share names with internal or official tools. This tactic aims to bypass security checks and social engineering defenses by appearing as a familiar and trusted component. The implications of this attack extend beyond individual developers, potentially impacting the security of applications built using these compromised dependencies and the integrity of the software supply chain as a whole. The researchers have alerted the npm security team and Alibaba to the findings, and efforts are underway to remove the malicious packages from the registry and mitigate the ongoing threat.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next