Cybersecurity · 31 views
Expired domain leads to supply chain attack on node-ipc npm package
A popular npm package called node-ipc has been compromised, with hackers publishing malicious versions that bundle credential stealing malware.
AI Summary
Hackers hijacked the maintainer account of the popular npm package node‑ipc by registering its expired domain name. They then published three trojanized releases—9.1.6, 9.2.3, and 12.0.1—each embedding an 80 KB obfuscated credential‑stealing payload in the node‑ipc.cjs file. The package, used by 424 projects and downloaded nearly 700 k times weekly, had previously been compromised in March 2022 when its creator added malicious code to target systems with Russian or Belarusian IP addresses. The new malicious versions replace legitimate code, enabling attackers to harvest credentials from any project that installs them.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- MFA's Weakest Link: Account Recovery Is the New Attack PathContinue reading
- US Agencies Warn China Is Systematically Extracting Frontier AI CapabilitiesContinue reading
- Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVEContinue reading
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without ApprovalContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow