PULSE NAME
Popular node-ipc npm Package Infected with Credential Stealer
WHITE AlienVault 2026-05-20 Modified: 2026-05-21
10
IOCs
LOW VOLUME
A supply chain attack has compromised the node-ipc npm package, with malicious versions 9.1.6, 9.2.3, and 12.0.1 containing obfuscated stealer and backdoor functionality. The attack vector involved takeover of a dormant maintainer account through an expired email domain. The malware fingerprints host environments, enumerates and reads local files including SSH keys, cloud credentials, database configurations, and various developer secrets. Collected data is compressed into a gzip archive and exfiltrated via DNS TXT queries to attacker-controlled infrastructure disguised as legitimate Azure domains. The payload targets over 100 file patterns across macOS and Linux systems, focusing on developer credentials from AWS, Azure, GCP, Kubernetes, Docker, npm, GitHub, and numerous other services. The malicious code executes during CommonJS module loading, forking a detached child process to perform credential harvesting while avoiding detection through obfuscation and DNS-based covert channels.
Indicators of Compromise (10)
All FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e 2026-05-20
FileHash-SHA256 78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981 2026-05-20
FileHash-SHA256 96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144 2026-05-20
FileHash-SHA256 bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301 2026-05-20
FileHash-SHA256 c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea 2026-05-20
IPv4 37.16.75.69 2026-05-20
URL http://sh.azurestaticprovider.net:443 2026-05-20
domain atlantis-software.net 2026-05-20
domain child.channel 2026-05-20
hostname sh.azurestaticprovider.net 2026-05-20