Socket
Book a DemoSign in
Socket

Supply Chain Attack Campaign

Ongoing

node-ipc

node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1 contained obfuscated stealer/backdoor behavior. The malware appears to fingerprint the host environment, enumerate and read local files, compress and chunk collected data, wrap the payload in a cryptographic envelope, and attempt exfiltration through a network endpoint selected via DNS/address logic.

Ecosystems: npm

First discovered
2026-05-14
Last activity
2026-05-14
Affected Package Artifacts
3
Package Artifacts Last 7 Days
3
100%
vs previous 7 days

Affected packages

Package ArtifactPublishedDetected

npm node-ipc 12.0.1

2026-05-14 14:25:30 UTC2026-05-14 14:29:40 UTC

npm node-ipc 9.1.6

2026-05-14 14:26:25 UTC2026-05-14 14:29:22 UTC

npm node-ipc 9.2.3

2026-05-14 14:26:01 UTC2026-05-14 14:29:20 UTC

Showing 3 of 3

SocketSocket SOC 2 Logo

Product

About

Packages

Stay in touch

Get open source security insights delivered straight into your inbox.

  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc

U.S. Patent No. 12,346,443 & 12,314,394. Other pending.