logo

node-ipc npm Package with 822K Weekly Downloads Compromised in Supply Chain Attack

ID: ebd1cda6-28ef-5e69-883e-f354e959dc5d

STIX ID: report--ebd1cda6-28ef-5e69-883e-f354e959dc5d

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-05-14

Date Updated: 2026-05-15

Author: Guru Baran

...
...

Malicious versions of the widely used node-ipc npm package ([email protected], @9.2.3, and @12.0.1) were published after a maintainer account takeover; the CommonJS entrypoint contains an obfuscated IIFE that fingerprints hosts, harvests credentials and many secret files, archives them, and exfiltrates data via DNS TXT queries to a fake Azure-like domain. The report provides SHA-256 hashes for malicious files, C2 domain and IP, a runtime env flag (__ntw=1), detection tips (DNS TXT bursts), and remediation guidance to remove versions and rotate potentially exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.