Covert npm malware campaign targets Alibaba developers
Security researchers uncovered a covert npm supply chain campaign targeting developers at Alibaba Group. The attack splits a malicious loader across benign packages to deploy a Remote Access Trojan (RAT) that poisons AI tool skills and propagates laterally via DingTalk.
Supply chain threats are evolving past traditional credential theft to directly exploit modern AI developer tools and enterprise chat software.
* **AI Tool Skill Poisoning:** Tampering with AI assistant and agent skill configurations creates a novel, highly persistent vector in AI-augmented developer environments.
* **Split Loader Evasion:** Fragmenting malicious logic across separate, harmless-looking npm packages successfully circumvents static analysis and dependency scanners.
* **Lateral Movement via DingTalk:** Utilizing enterprise collaboration tools like DingTalk allows the Trojan to automatically propagate through internal corporate networks.
DISCOVERED
2h ago
2026-07-28
PUBLISHED
2h ago
2026-07-28
RELEVANCE
AUTHOR
SocketSecurity