Corepack Search Trap Steals Dev Credentials

The danger is the fake download path, not a bad Corepack package. Developers who search for the tool after Node.js stopped bundling it can land on a lookalike site that turns a routine install into credential theft and proxy abuse on the workstation. Corepack is supposed to come from npm, not a Windows .exe. Socket says corepack[.]org has moved from a low-quality imitation to active binary delivery, and the payload steals browser-profile data and stored SSH keys while enrolling the host in a bandwidth-sharing proxy network. That makes search-driven tool installs a direct attack surface for developer endpoints. If teams still rely on web search and “official-looking” sites for developer tooling, the spoof can take both secrets and machine trust at the same time.

Part of the PlainSec briefing for 2026-07-25

Sources