The images in this article were generated with artificial intelligence. How we publish
Security investigators have identified a attack on the supply chain that uses malicious npm packages to target developers using Alibaba ecosystem tools. The technique is not a single single package with malicious code, but a layer structure where apparently harmless versions and "decoy" packages with names identical to private packages of the @ ali field activate a network of dependencies that finally download and run a complex backdoor.
The initial vector included non-scanned packages such as lib-mtop, which matches in name a private package of Alibaba, and several additional bookstores published from the same maintenance account. Public versions passed changes in March / April that added a loader capable of obtaining a remote payload (invoking curl) and running JavaScript code delimited by a "rule engine" that uses the Node.js vm module to decide behavior by operating system.

The campaign shows a careful design to evade detection: the secondary payload is downloaded from a domain that imitates Alibaba and the malicious code is fragmented in several packages of the chain of dependencies, so that the package that the developer installs acts as decoy and the real logic materializes through middle- and low- layer packages. This separation makes manual and automated analysis of rapid unit reviews difficult.
The final payload is a RAT multiplatform with remote running capabilities, exfiltration, host recognition, staging of additional loads and lateral movement. In Windows it replaces or troyanizes corporate security components and apps; in Linux it downloads binary in / tmp and runs them in memory; in macOS it modifies shell starts and creates Launch Agents. It can also persist by injecting code into business collaboration applications such as DingTalk, increasing the risk of targeted espionage.
Although the attribution is not confirmed, there are operational signs in the Chinese comments and in time marks with UTC + 08: 00 that point to a Chinese-speaking actor. The apparent objective is the industrial espionage against developers in companies linked to the Alibaba Group, which makes this campaign a strategic risk rather than a simple mass malware campaign.
If you have installed any of the associated packages (e.g. lib-mtop, aone-kit, smart-config-manager, local-config-parser and other related packages), you must commitment and act immediately from clean machines. Priority actions include rotating credentials and keys from a team you know is not engaged; auditioning development systems and CI in search of persistent processes; and looking for indicators such as ~ / .zshrc, LaunchAgens in macOS, binaries executed from / tmp in Linux and DLs services modified in Windows.
In addition, it is appropriate to check repositories and CI flows: review and rotate Npm publication tokens and GitHub credentials, disable self-housed runners to audit their status and extinguish possible filtering webbooks. Simple check commands can help: check package-lock.json / yarn.lock, run npm lsin projects, and look for the package name chains in the dependencies tree. It is also recommended to clean hogs and reinstall dependencies from reliable lockfiles or from an internal registry.

To mitigate future risks, it activates multi-factor authentication in npm and GitHub accounts, limits publication permissions per team, uses check-ups in pull requests and considers blocking policies for non-scopeed packages that may impersonate internal names. Supply chain review and unit scanning tools can automate early detection; GitHub's documentation on supply chain security and npm's guide on safe practices are good starting points for implementing controls: GitHub supply chain security guide and Good safety practices of npm.
If you manage an organization, you value the use of a private register or proxy policies that allow you to audit and approve packages before consumption in corporate environments, and monitor the outgoing traffic to suspicious domains (for example that used by the attackers to mimic ODS of Alibaba). For additional unit analysis and scanning, projects such as OWASP Dependency-Check offer useful resources to identify committed components: OWASP Dependency-Check.
In short, this incident reinforces that the security of modern software depends both on hygiene in repositories and CI environments and on strict control of which packages are allowed in production. The deliberate fragmentation of malicious functionality in multiple modules and the use of lures that imitate private packages underline the importance of organizational controls (publishing policies, minimum permissions) and technical (automated scanning, egress monitoring and persistence detection) to reduce the attack surface.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...