#nodeipc
Malicious code found in node-ipc 9.1.6, 9.2.3, and 12.0.1 steals AWS, GCP, Azure, SSH, and GitHub secrets, fingerprints hosts, and quietly exfiltrates data via hidden backdoors. #nodeipc #StepSecurity #JavaScript
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
Researchers found malicious code in node-ipc versions 9.1.6, 9.2.3, and 12.0.1 that steals developer and cloud credentials, fingerprints the host, and exfiltrates data to a command-and-control domain. The campaign uses obfuscated payloads, DNS-based evasion, and background child processes to quietly continue stealing secrets from affected systems. #nodeipc #sazurestaticprovidernet #Socket #StepSecurity...
www.hendryadrian.com
May 15, 2026 at 7:00 AM
Malicious republished node-ipc npm releases 9.1.6, 9.2.3, and 12.0.1 were caught stealing developer secrets, fingerprinting hosts, and exfiltrating data via DNS TXT queries. #nodeipc #NpmSupplyChain #NodeJS
Popular node-ipc npm Package Infected with Credential Stealer
Socket detected malicious republished versions of node-ipc that steal developer secrets, fingerprint hosts, and exfiltrate data through DNS TXT queries. The incident affects node-ipc 9.1.6, 9.2.3, and 12.0.1, with historical malicious releases 10.1.1, 10.1.2, 11.0.0, and 11.1.0 tied to the 2022 compromise. #node-ipc #TekDefense #Permiso
www.hendryadrian.com
May 16, 2026 at 4:00 AM
🔴 node-ipc 新版本包含凭据收集等恶意行为。

- 涉及版本 9.1.6/9.2.3/12.0.1。
- 这些版本由一位已有权限但久未维护此包的维护者发布。
- 这已经是 node-ipc 二进宫了;上次是因为 peacenotwar。

https://socket.dev/blog/node-ipc-package-compromised

thread: /3471
linksrc: https://t.me/landiansub/15345

#NodeIPC

Telegram 原文
May 15, 2026 at 12:58 AM
Mini Shai-Hulud: TeamPCP compromette 160+ pacchetti npm e PyPI in un supply chain attack che ha colpito TanStack, Mistral AI e OpenAI
il blog: insicurezzadigitale.com/mini-shai-hu...

#cybersecurity #cybercrime #githubactions #infosec #malware #nodeipc #npm #pypi #supplychain #tanstack #teampcp
May 19, 2026 at 8:04 AM
Popular node-ipc npm versions were compromised in a supply-chain attack, stealing cloud, SSH, Kubernetes, Docker, npm, GitHub, GitLab, and database credentials via DNS TXT exfiltration. #nodeipc #npm #SupplyChain
Popular node-ipc npm package compromised to steal credentials
A supply-chain attack has injected credential-stealing malware into malicious node-ipc versions on npm, affecting a package that is downloaded more than 690,000 times each week. The infostealer collects cloud and developer credentials, then exfiltrates the stolen data using DNS TXT queries after the maintainer account 'atiertant' was compromised. #node-ipc #npm #atiertant
www.hendryadrian.com
May 15, 2026 at 9:45 PM
Malicious node-ipc npm releases 9.1.6, 9.2.3, and 12.0.1 hide a backdoor in node-ipc.cjs, stealing developer creds and host data via DNS TXT exfiltration under bt.node.js. #nodeipc #npm #DNS
Backdoored node-ipc npm releases steal developer credentials through DNS queries
Three node-ipc npm releases, 9.1.6, 9.2.3, and 12.0.1, were published on May 14, 2026 with a backdoored CommonJS entrypoint that collects credentials and host data. The payload exfiltrates archives over DNS to sh.azurestaticprovider.net:443 using TXT queries under bt.node.js, with indicators including node-ipc.cjs, __ntw=1, and the affected package versions. #node-ipc #sh.azurestaticprovider.net #bt.node.js
www.hendryadrian.com
May 15, 2026 at 12:00 AM