Expired domain leads to supply chain attack on node-ipc npm package | HappeningNow.news
Breaking

Cybersecurity · 30 views

Expired domain leads to supply chain attack on node-ipc npm package

A popular npm package called node-ipc has been compromised, with hackers publishing malicious versions that bundle credential stealing malware.

Source AI Summary Published May 15, 2026 Brief Under 1 min brief
Story intelligence
Coverage Checking
Views 30 Community interest
Brief read Under 1 min brief 90 words

AI Summary

Hackers hijacked the maintainer account of the popular npm package node‑ipc by registering its expired domain name. They then published three trojanized releases—9.1.6, 9.2.3, and 12.0.1—each embedding an 80 KB obfuscated credential‑stealing payload in the node‑ipc.cjs file. The package, used by 424 projects and downloaded nearly 700 k times weekly, had previously been compromised in March 2022 when its creator added malicious code to target systems with Russian or Belarusian IP addresses. The new malicious versions replace legitimate code, enabling attackers to harvest credentials from any project that installs them.

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used
Read original at Csoonline

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page