logo

Popular node-ipc npm package compromised to steal credentials

ID: 2beb0155-d1d8-5935-b8ce-eef316eb17db

STIX ID: report--2beb0155-d1d8-5935-b8ce-eef316eb17db

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Bill Toulas

...
...

Hackers injected an obfuscated credential-stealing backdoor into three published node-ipc npm package versions (9.1.6, 9.2.3, 12.0.1) that automatically runs when applications load, fingerprints systems, collects cloud and local credentials, compresses data and exfiltrates via DNS TXT queries; researchers attribute the compromise to an external actor who accessed an inactive maintainer's account and recommend removing affected versions, rotating secrets, and inspecting caches and lockfiles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.