Node-IPC npm Package With 822K Weekly Downloads Compromised With Infostealer Backdoor
On May 14,
The compromise exploits npm's account recovery architecture: expired recovery-email domains for dormant co-maintainers create a replicable, low-cost takeover surface across the ecosystem. The 56-second, three-version publication window and byte-identical payloads, per converging independent analyses from Socket and SafeDep, very likely reflect pre-staged automated tooling and deliberate operation. The SHA-256 fingerprint gate in 12.0.1, pre-computed against a specific target's module entry point before publication, confirms prior reconnaissance against a named victim. The narrowly targeted espionage operation was likely the main effort, with broad 9.x credential harvesting as collection cover. The exfiltration channel overrides the system resolver, routing queries directly to the C2 IP and leaving corporate DNS logs clean.
4 sources
- node-ipc npm Package with 822K Weekly Downloads Compromised in Supply Chain Attack -
Cyber Security News - Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets -
The Hacker News - Compromised node-ipc on npm: Credential Stealer via DNS Exfiltration -
SafeDep - Socket detected malicious activity in newly published versions of node-ipc -
Socket Security (X)