On May 14, 2026 multiple malicious versions of the npm package node-ipc (9.1.6, 9.2.3, 12.0.1) were published to the npm registry containing an obfuscated credential‑stealer/backdoor. The payload is added to node-ipc.cjs and triggers when the package is loaded via require("node-ipc"); early analysis suggests abuse of a maintainer account rather than CI compromise and Snyk published advisory SNYK-JS-NODEIPC-16697063.
Part of the PlainSec briefing for 2026-05-14