← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
The Supply Chain Strikes Again: Credential-Stealing Malware Hidden in node-ipc
On May 14, 2026, attackers published malicious versions of the widely used npm package node-ipc through a legitimate maintainer account, embedding a sophisticated credential-stealing payload in a package that had previously garnered around 3.35 million monthly downloads. The malware was concealed within the CommonJS bundle, specifically in the node-ipc.cjs file, and activated silently when applications loaded the package using the require('node-ipc') command. This strategic design ensured that the malware harvested sensitive credentials related to developer environments, CI/CD pipelines, and cloud services without interfering with the normal application operation, allowing it to function stealthily.
Indicators of Compromise (5)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | d1ba0419cb5e5de91b9b58e87b8322e1 | — | 2026-05-20 | |
| FileHash-SHA256 | 96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144 | — | 2026-05-20 | |
| IPv4 | 37.16.75.69 | CC=NL ASN=AS43641 sollutium eu sp z.o.o. | 2026-05-20 | |
| domain | azurestaticprovider.net | — | 2026-05-20 | |
| hostname | sh.azurestaticprovider.net | — | 2026-05-20 |