Cybersecurity — 2026-05-14

Node-IPC npm Package With 822K Weekly Downloads Compromised With Infostealer Backdoor

BLUFDormant co-maintainer accounts secured by expired recovery-email domains constitute a structural weakness in npm's trust model that adversaries can exploit cheaply to stage targeted espionage under the cover of mass credential theft.

On May 14, Socket and StepSecurity confirmed that node-ipc versions 9.1.6, 9.2.3, and 12.0.1 carry byte-identical obfuscated payloads harvesting over 100 credential categories, including cloud provider keys, SSH credentials, and AI coding tool settings. SafeDep's primary analysis found the payload appended to node-ipc.cjs as an IIFE firing on require(), exfiltrating data via DNS TXT queries to sh[.]azurestaticprovider[.]net with the system resolver overridden to sidestep corporate DNS monitoring. Ian Ahl of Permiso identified the likely attack vector as acquisition of the expired recovery email domain for "atiertant," a dormant co-maintainer account, enabling an npm password reset and unauthorized publish rights. SafeDep reported all three versions were published within 56 seconds; 12.0.1 was tagged latest, exposing any unpinned install.

Analysis
The compromise exploits npm's account recovery architecture: expired recovery-email domains for dormant co-maintainers create a replicable, low-cost takeover surface across the ecosystem. The 56-second, three-version publication window and byte-identical payloads, per converging independent analyses from Socket and SafeDep, very likely reflect pre-staged automated tooling and deliberate operation. The SHA-256 fingerprint gate in 12.0.1, pre-computed against a specific target's module entry point before publication, confirms prior reconnaissance against a named victim. The narrowly targeted espionage operation was likely the main effort, with broad 9.x credential harvesting as collection cover. The exfiltration channel overrides the system resolver, routing queries directly to the C2 IP and leaving corporate DNS logs clean.
4 sources
  1. node-ipc npm Package with 822K Weekly Downloads Compromised in Supply Chain Attack - Cyber Security News
  2. Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets - The Hacker News
  3. Compromised node-ipc on npm: Credential Stealer via DNS Exfiltration - SafeDep
  4. Socket detected malicious activity in newly published versions of node-ipc - Socket Security (X)

View in full brief →

UNCLASSIFIED // OPEN SOURCE