Malicious node-ipc npm Packages Trigger New Supply Chain Security Alarm
ID: b8e89471-5253-59cd-8162-c64a80a67b25
STIX ID: report--b8e89471-5253-59cd-8162-c64a80a67b25
Feed Name: The Cyber Express
A supply-chain compromise of the widely used node-ipc npm package delivered an obfuscated credential-stealing backdoor in the CommonJS build; attackers likely regained publishing access by re-registering an expired maintainer email domain and pushed multiple malicious releases that harvest developer and CI secrets, create compressed archives, and exfiltrate data via大量 DNS TXT queries. Researchers flagged infected tarballs quickly, published SHA-256 hashes and remediation guidance, and noted forensic indicators (e.g., uniform Oct 26, 1985 timestamps) to help identify contaminated caches and artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
