PULSE NAME
The Supply Chain Strikes Again: Credential-Stealing Malware Hidden in node-ipc
WHITE PetrP.73 2026-05-20 Modified: 2026-05-20
5
IOCs
LOW VOLUME
On May 14, 2026, attackers published malicious versions of the widely used npm package node-ipc through a legitimate maintainer account, embedding a sophisticated credential-stealing payload in a package that had previously garnered around 3.35 million monthly downloads. The malware was concealed within the CommonJS bundle, specifically in the node-ipc.cjs file, and activated silently when applications loaded the package using the require('node-ipc') command. This strategic design ensured that the malware harvested sensitive credentials related to developer environments, CI/CD pipelines, and cloud services without interfering with the normal application operation, allowing it to function stealthily.
Indicators of Compromise (5)
All FileHash-MD5 FileHash-SHA256 IPv4 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 d1ba0419cb5e5de91b9b58e87b8322e1 2026-05-20
FileHash-SHA256 96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144 2026-05-20
IPv4 37.16.75.69 CC=NL ASN=AS43641 sollutium eu sp z.o.o. 2026-05-20
domain azurestaticprovider.net 2026-05-20
hostname sh.azurestaticprovider.net 2026-05-20