A spoofed Corepack website, corepack[.]org, was used to lure users into downloading malicious Windows installers instead of legitimate package-manager setup guidance. Reporting indicates the site redirected visitors to malware-linked download paths, including an OpenShield-hosted payload, vpnsetup_d9gfqvs3dsic73fcvi90[.]exe, associated with infostealer activity, hidden proxyware enrollment, and persistence via Windows Run keys. Observed behavior included access to browser profiles and SSH keys, host and process discovery, and command-shell execution, raising concern that developer credentials and active sessions may have been exposed.
A separate delivery path served OperaGXSetup[.]exe through a deceptive download page and was described as an adware-style installer chain with trojan-like signals. The campaign appears designed to exploit confusion among developers and Windows users seeking Corepack after Node.js distribution changes. Users who ran the installers are being urged to treat browser sessions, SSH keys, developer tokens, and related credentials as compromised, rebuild or thoroughly clean affected systems, and rotate credentials from a trusted device.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Socket published an analysis on July 24, 2026 describing a fake Corepack website, corepack[.]org, that impersonated the legitimate project and redirected Windows users to malware-linked download paths. The reported delivery chains included an infostealer/proxyware installer and a separate adware-style installer path.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcetrojan-killer.net
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.