Vulnerabilità · 138 giorni fa
Una dipendenza pubblicata di recente non è sicura solo perché proviene dal maintainer. In questo caso, node-ipc 9.1.6, 9.2.3 e 12.0.1 sono il payload, e il vero raggio d'esplosione è qualsiasi workstation di sviluppatore o job CI che li carica a runtime ed espone secret locali.
6 fonti che coprono questa storia
Popular node-ipc npm package compromised to steal credentials
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm.
Malicious node-ipc Versions Published to npm | Snyk
Malicious node-ipc versions on npm may have stolen credentials from developer and CI/CD environments.
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
Three node-ipc versions contain stealer/backdoor code, exposing developer and cloud secrets to exfiltration.
Popular node-ipc npm Package Infected with Credential Steale...
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.
An analysis of backdoored node-ipc npm releases that add an obfuscated credential collection and DNS exfiltration payload to the CommonJS entrypoint.
Not Your IPC, but node-ipc: npm Hit Again with Supply Chain Attack (But This Time It's Not a Worm)
Newly published versions of the node-ipc npm package briefly contained an obfuscated infostealer that harvested developer credentials, cloud tokens, SSH keys, CI/CD secrets, and local configuration files before attempting DNS-based exfiltration.
Part of the PlainSec briefing for 2026-05-14