Several newly published versions of the widely used npm package node-ipc were found to be malicious after being released through the legitimate maintainer account, turning a trusted dependency into an active software supply chain attack. Researchers identified node-ipc@9.1.6, 9.2.3, and 12.0.1 as compromised, with the payload embedded in the package’s CommonJS bundle so it executed when applications loaded the library while normal functionality continued. Security firms said any project installing the package directly or transitively could be affected, and described the code as an obfuscated stealer and backdoor that fingerprints hosts, reads local files, and attempts covert data theft.
Analysis indicates the malware harvested environment variables and secrets from developer workstations, CI/CD pipelines, cloud platforms, Kubernetes, Docker, SSH configurations, browser profiles, and AI tooling, then compressed, encrypted, and exfiltrated the data through DNS TXT queries using public resolvers and attacker-controlled infrastructure including azurestaticprovider.net, sh.azurestaticprovider.net, bt.node.js, and 37.16.75.69. Investigators said the use of the legitimate maintainer account points to either account compromise or insider abuse, while the campaign appears focused on infrastructure-aware credential theft rather than disruption. Defenders were urged to remove the affected versions from manifests and lockfiles, pin to known-clean releases, audit systems that installed them, and rotate all secrets exposed in any impacted CI/CD environment.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
Investigators said the node-ipc compromise may have begun when attackers took over a dormant npm maintainer account tied to an expired email domain that was re-registered in May 2026. This provided a plausible explanation for how malicious versions 9.1.6, 9.2.3, and 12.0.1 were published through the legitimate maintainer account.
On 2026-05-14, StepSecurity reported that the malicious node-ipc version 12.0.1 included a SHA-256 fingerprint check that made the payload inert except on a specific targeted environment. In contrast, the malicious 9.x releases were described as broadly executing, indicating different targeting behavior across the compromised versions.
By 2026-05-14, deeper analysis showed the malicious code was appended to the CommonJS bundle node-ipc.cjs and harvested secrets from developer systems, CI/CD, cloud, Kubernetes, Docker, SSH, browser profiles, and AI tooling. Upwind reported that the malware compressed and encrypted stolen data, exfiltrated it via DNS TXT queries using public resolvers, and tied the activity to infrastructure including azurestaticprovider.net, sh.azurestaticprovider.net, bt.node.js, and 37.16.75.69.
Initial reverse engineering on 2026-05-14 found that the compromised package contained an obfuscated payload that executed when node-ipc was required at runtime. Researchers said it could fingerprint hosts, read local files, steal developer and cloud secrets, and attempt exfiltration to attacker-controlled infrastructure.
Shortly after publication on 2026-05-14, security researchers at Socket and StepSecurity reported that the new node-ipc releases were malicious and warned that projects installing them directly or transitively were affected. They advised developers to remove the affected versions, pin to known-clean releases, and audit impacted environments.
On 2026-05-14, malicious releases of the widely used npm package node-ipc were published through the legitimate maintainer account atiertant. The compromised versions identified across reports were 9.1.6, 9.2.3, and 12.0.1.
In March 2022, node-ipc maintainer Brandon Nozaki Miller intentionally introduced protestware into multiple package releases, including destructive file corruption in versions 10.1.1 and 10.1.2 for systems geolocated in Russia or Belarus. Later releases 11.0.0, 11.1.0, and 9.2.2 pulled in the peacenotwar dependency, spreading disruptive behavior transitively to downstream projects such as Vue.js CLI.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
14 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcesnyk.io
Open sourcethreats.wiz.io
Open sourcestepsecurity.io
Open sourcesnyk.io
Open sourcesnyk.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.