Popular node-ipc npm Library Hit by Supply Chain Attack, Impacting 822K Weekly Downloads
ID: 28ac6a1b-9c22-5799-ba89-5a17d86b4ecd
STIX ID: report--28ac6a1b-9c22-5799-ba89-5a17d86b4ecd
Feed Name: GBHackers
Threat Score
A supply-chain attack was discovered in the widely used node-ipc npm package: multiple malicious CommonJS versions (including 9.2.3 and 12.0.1) silently collect developer and cloud credentials, compress and encrypt them, and exfiltrate via thousands of DNS TXT queries to attacker-controlled domains; investigators link the incident to a likely maintainer account takeover and provide IOCs and remediation steps (remove affected versions, audit dependencies, rotate keys, and monitor DNS).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
