node-ipc npm Package with 822K Weekly Downloads Compromised in Supply Chain Attack
ID: ebd1cda6-28ef-5e69-883e-f354e959dc5d
STIX ID: report--ebd1cda6-28ef-5e69-883e-f354e959dc5d
Feed Name: cybersecurityNews.com
Malicious versions of the widely used node-ipc npm package ([email protected], @9.2.3, and @12.0.1) were published after a maintainer account takeover; the CommonJS entrypoint contains an obfuscated IIFE that fingerprints hosts, harvests credentials and many secret files, archives them, and exfiltrates data via DNS TXT queries to a fake Azure-like domain. The report provides SHA-256 hashes for malicious files, C2 domain and IP, a runtime env flag (__ntw=1), detection tips (DNS TXT bursts), and remediation guidance to remove versions and rotate potentially exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
