As cited
Copy frozen at (site build).
threat intel
Backdoored node-ipc npm releases steal developer credentials through DNS queries
Backdoored versions of the node-ipc npm package were distributed with obfuscated code that collects developer credentials and exfiltrates them via DNS queries. The malicious payload is injected into the CommonJS entrypoint, affecting developers who install the compromised releases.
Why it matters: Supply chain attack on npm developers: anyone using backdoored node-ipc releases may have credentials stolen and should audit installed versions immediately.
- Source published
- First seen by Cybersecurity Tracker