Attackers distributed malicious functionality across a cluster of npm packages that impersonate private Alibaba (@ali scope) packages, triggering a multi-stage download chain that ultimately deploys a cross-platform RAT named aone-cli. The malware employs a Node.js vm sandbox-escape technique to gain process-level access, uses Alibaba Cloud OSS and a compromised GitHub repository to blend malicious traffic with legitimate infrastructure, and establishes persistence via shell profile modification, Launch Agents, code injection into AI tooling, and replacement of a legitimate security application's core code on Windows.
vm sandbox escape
1 post
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers