The danger is the fake download path, not a bad Corepack package. Developers who search for the tool after Node.js stopped bundling it can land on a lookalike site that turns a routine install into credential theft and proxy abuse on the workstation.
Corepack is supposed to come from npm, not a Windows .exe. Socket says corepack[.]org has moved from a low-quality imitation to active binary delivery, and the payload steals browser-profile data and stored SSH keys while enrolling the host in a bandwidth-sharing proxy network.
That makes search-driven tool installs a direct attack surface for developer endpoints. If teams still rely on web search and “official-looking” sites for developer tooling, the spoof can take both secrets and machine trust at the same time.