logo

Malicious node-ipc npm Packages Trigger New Supply Chain Security Alarm

ID: b8e89471-5253-59cd-8162-c64a80a67b25

STIX ID: report--b8e89471-5253-59cd-8162-c64a80a67b25

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-05-15

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

A supply-chain compromise of the widely used node-ipc npm package delivered an obfuscated credential-stealing backdoor in the CommonJS build; attackers likely regained publishing access by re-registering an expired maintainer email domain and pushed multiple malicious releases that harvest developer and CI secrets, create compressed archives, and exfiltrate data via大量 DNS TXT queries. Researchers flagged infected tarballs quickly, published SHA-256 hashes and remediation guidance, and noted forensic indicators (e.g., uniform Oct 26, 1985 timestamps) to help identify contaminated caches and artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.