{
  "name": "Popular node-ipc npm Package Infected with Credential Stealer",
  "slug": "popular-node-ipc-npm-package-infected-with-credential-stealer",
  "description": "A supply chain attack has compromised the node-ipc npm package, with malicious versions 9.1.6, 9.2.3, and 12.0.1 containing obfuscated stealer and backdoor functionality. The attack vector involved takeover of a dormant maintainer account through an expired email domain. The malware fingerprints host environments, enumerates and reads local files including SSH keys, cloud credentials, database configurations, and various developer secrets. Collected data is compressed into a gzip archive and exfiltrated via DNS TXT queries to attacker-controlled infrastructure disguised as legitimate Azure domains. The payload targets over 100 file patterns across macOS and Linux systems, focusing on developer credentials from AWS, Azure, GCP, Kubernetes, Docker, npm, GitHub, and numerous other services. The malicious code executes during CommonJS module loading, forking a detached child process to perform credential harvesting while avoiding detection through obfuscation and DNS-based covert channels.",
  "published": "2026-05-20T11:12:14.364000+00:00",
  "created_at": "2026-05-21T16:46:49.626000+00:00",
  "modified_at": "2026-05-21T14:46:50+00:00",
  "created_at_opencti": "2026-05-21T16:46:49.626000+00:00",
  "author": "AlienVault",
  "confidence": 100,
  "report_types": [
    "threat-report"
  ],
  "labels": [
    "credential stealer",
    "developer secrets harvesting",
    "dns exfiltration",
    "maintainer account takeover",
    "node-ipc compromise",
    "npm package compromise",
    "supply chain attack"
  ],
  "tags": [
    "2026-05-20",
    "credential-stealer",
    "developer secrets harvesting",
    "dns exfiltration",
    "maintainer account takeover",
    "node-ipc compromise",
    "npm package compromise",
    "supply chain attack"
  ],
  "related_entities": {
    "indicators": [
      {
        "id": "d9ee2ca2-0521-4a2a-a4db-0e5dd6c022d3",
        "name": "child.channel"
      },
      {
        "id": "77e8e345-7559-4f2d-93c0-96bb9f1831c5",
        "name": "atlantis-software.net"
      },
      {
        "id": "49f006a2-201f-4175-a855-0a5d297ff4c7",
        "name": "449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e"
      },
      {
        "id": "053953b4-41b9-4693-be99-b510f09496b7",
        "name": "37.16.75.69"
      },
      {
        "id": "c9b5bcb2-98b5-4dec-836e-315080eb548f",
        "name": "bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301"
      },
      {
        "id": "2a4a36de-529a-4a6c-bbd1-1a7cb40231a8",
        "name": "96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144"
      },
      {
        "id": "b28ba363-2574-4508-8bad-327054d1f990",
        "name": "sh.azurestaticprovider.net"
      },
      {
        "id": "e66daa4d-ccd3-48bf-bfec-8c43e30cb92f",
        "name": "http://sh.azurestaticprovider.net:443"
      },
      {
        "id": "b0f442dc-414d-4feb-8a37-098db6c6b664",
        "name": "78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981"
      },
      {
        "id": "1cbda1ae-bc4e-47cc-b808-448b931bb841",
        "name": "c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea"
      }
    ],
    "attack_patterns": [
      {
        "id": "8c79f5d6-60f2-4b5c-9b44-3e00ce9294d0",
        "name": "T1074.001"
      },
      {
        "id": "9f11a241-9abc-4c57-95dd-33955ab08826",
        "name": "T1078"
      },
      {
        "id": "9322d33b-00c1-4f99-9f1a-a33d93c0dac2",
        "name": "T1059.007"
      },
      {
        "id": "e615d5ec-8d67-4048-b21d-a5fb09925bb9",
        "name": "T1552.001"
      },
      {
        "id": "9f21708c-24b6-46b5-bf7e-522256e8470c",
        "name": "T1552.004"
      },
      {
        "id": "97d377d8-89c7-48f8-a79f-0f48bd60df74",
        "name": "T1005"
      },
      {
        "id": "0c836307-129e-4ff7-a532-180c633cacba",
        "name": "T1027"
      },
      {
        "id": "1584b551-72fb-4f60-ba7a-bdac106e6f9b",
        "name": "T1560.001"
      },
      {
        "id": "1d0d9e67-eb8a-439c-a2c7-cab311bb25c4",
        "name": "T1195.002"
      },
      {
        "id": "41ad5d62-aa6a-47d6-a9a9-fb2209601099",
        "name": "T1098"
      },
      {
        "id": "19ce62bb-3faf-4d09-90b1-d82fce1ba8b0",
        "name": "T1136"
      },
      {
        "id": "2d8a4c76-3094-4914-b163-55b3dee82191",
        "name": "T1048.003"
      },
      {
        "id": "6efb8bea-11d7-418d-a429-9f4a3e6c50f6",
        "name": "T1087"
      },
      {
        "id": "436e795b-553f-444e-b837-65818d8f539f",
        "name": "T1119"
      },
      {
        "id": "e1b18ecf-d74e-4fe6-9bd4-ca6a62e7d818",
        "name": "T1027.002"
      },
      {
        "id": "ce39cd5d-9e4c-4138-b546-abd68e57f8c2",
        "name": "T1071.004"
      },
      {
        "id": "45082a8e-9c79-470e-ad1b-decac7188e8f",
        "name": "T1083"
      },
      {
        "id": "232fbdfa-94c6-443d-b575-373e75b4f4c2",
        "name": "T1567"
      },
      {
        "id": "70616b2f-4019-4963-b758-5d9f6f20e201",
        "name": "T1082"
      },
      {
        "id": "fa3b8b48-d97c-4242-83a6-07d435a5a79e",
        "name": "T1041"
      }
    ],
    "malware": [
      {
        "id": "a2ca9568-9fc8-4b92-a09d-d3b04b4f03b8",
        "name": "node-ipc",
        "slug": "node-ipc"
      }
    ],
    "observables": [
      {
        "id": "2a4c10d4-833d-4902-b14f-575c8986c5df",
        "name": "atlantis-software.net"
      },
      {
        "id": "0cdfa0f8-3ef3-4ad8-b887-f0839bbf768d",
        "name": "child.channel"
      },
      {
        "id": "c4f62d0f-a1df-4f03-81ca-8ed77ae0289d",
        "name": "sh.azurestaticprovider.net"
      },
      {
        "id": "554033cf-df8b-4f06-951e-833d10d88b21",
        "name": "37.16.75.69"
      },
      {
        "id": "74d5d76c-1849-4633-a199-140b8206bded",
        "name": "http://sh.azurestaticprovider.net:443"
      },
      {
        "id": "",
        "name": "449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e"
      },
      {
        "id": "",
        "name": "bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301"
      },
      {
        "id": "",
        "name": "96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144"
      },
      {
        "id": "",
        "name": "78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981"
      },
      {
        "id": "",
        "name": "c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "Technologies"
      },
      {
        "id": "",
        "name": "child.channel"
      },
      {
        "id": "",
        "name": "atlantis-software.net"
      },
      {
        "id": "",
        "name": "sh.azurestaticprovider.net"
      }
    ]
  },
  "external_refs": [
    {
      "id": "4387d9bb-fe0d-4a66-987c-837a1c71137a",
      "standard_id": "external-reference--1c5ff4ca-3c02-5ccb-a979-1acff8086c00",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://otx.alienvault.com/pulse/6a0d970e99916e7e7e17c893",
      "hash": null,
      "external_id": "6a0d970e99916e7e7e17c893",
      "created": "2026-05-21T16:46:49.501Z",
      "modified": "2026-05-21T16:46:49.501Z",
      "createdById": null
    },
    {
      "id": "fd3a6507-87b2-4f6b-aeec-81b4301c967a",
      "standard_id": "external-reference--b08b9ab3-b0a2-5109-8d5b-8828c5272b99",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://socket.dev/blog/node-ipc-package-compromised",
      "hash": null,
      "external_id": null,
      "created": "2026-05-21T16:46:49.547Z",
      "modified": "2026-05-21T16:46:49.547Z",
      "createdById": null
    }
  ]
}