Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
ID: c8038e96-73c7-5669-b1be-17b7c30aae90
STIX ID: report--c8038e96-73c7-5669-b1be-17b7c30aae90
Feed Name: The Hacker News
Malicious versions of the widely used npm package node-ipc (9.1.6, 9.2.3, 12.0.1) were published by an account that appears unrelated to the original maintainer; the packages include obfuscated stealer/backdoor code that fingerprints hosts, harvests a broad set of developer and cloud secrets, compresses them into a GZIP archive, and exfiltrates data to sh.azurestaticprovider.net and via DNS TXT records using a direct-to-C2 resolver technique. The 12.0.1 build includes a SHA-256 gating mechanism to target specific entry points, while the 9.x builds execute broadly; recommended actions include removing the compromised versions, rolling credentials, auditing publish/workflow activity, and blocking egress to the C2 domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
