Threats · 52 days ago
The danger is the fake download path, not a bad Corepack package. Developers who search for the tool after Node.js stopped bundling it can land on a lookalike site that turns a routine install into credential theft and proxy abuse on the workstation.
Corepack is supposed to come from npm, not a Windows .exe. Socket says corepack[.]org has moved from a low-quality imitation to active binary delivery, and the payload steals browser-profile data and stored SSH keys while enrolling the host in a bandwidth-sharing proxy network.
That makes search-driven tool installs a direct attack surface for developer endpoints. If teams still rely on web search and “official-looking” sites for developer tooling, the spoof can take both secrets and machine trust at the same time.
1 source covering this story
Fake Corepack Site Distributes Infostealer and Proxyware to ...
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
Part of the PlainSec briefing for 2026-07-25