Popular node-ipc npm package compromised to steal credentials

Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm.

BleepingComputer

Node-ipc Package Infected with Credential-Stealing Malware

A malicious update to the widely-used node-ipc library has infected thousands of projects with credential-stealing malware, posing a significant supply-chain risk for developer environments and CI systems. With over 690,000 weekly downloads, this single compromised library could be exfiltrating sensitive data from countless unsuspecting users.

https://osintsights.com/node-ipc-package-infected-with-credential-stealing-malware?utm_source=mastodon&utm_medium=social

#SupplyChain #CredentialStealing #Malware #Nodeipc #Npm

Node-ipc Package Infected with Credential-Stealing Malware

Learn how the node-ipc package was infected with credential-stealing malware and take immediate action to secure your developer environments now.

OSINTSights

Malicious Node-IPC Versions Expose Developer Secrets to Stealer Backdoor

Three versions of the popular Node IPC package have been compromised with a stealthy backdoor that can steal sensitive developer secrets, sparking urgent concerns about supply-chain security. The malicious versions, published under a fake account, contain heavily obfuscated code that springs into action when the package is loaded at…

https://osintsights.com/malicious-node-ipc-versions-expose-developer-secrets-to-stealer-backdoor?utm_source=mastodon&utm_medium=social

#MaliciousNodeipc #StealerBackdoor #SupplyChain #Npm #Nodeipc

Malicious Node-IPC Versions Expose Developer Secrets to Stealer Backdoor

Discover malicious Node-IPC versions exposing developer secrets to stealer backdoor. Learn how to protect your project now and prevent similar attacks from happening.

OSINTSights
CVE-2022-23812 | RIAEvangelist/node-ipc is malware / protest-ware

CVE-2022-23812 | RIAEvangelist/node-ipc is malware / protest-ware - readme.md

Gist
CVE-2022-23812 | RIAEvangelist/node-ipc is malware / protest-ware

CVE-2022-23812 | RIAEvangelist/node-ipc is malware / protest-ware - readme.md

Gist