← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Popular node-ipc npm Package Infected with Credential Stealer
A supply chain attack has compromised the node-ipc npm package, with malicious versions 9.1.6, 9.2.3, and 12.0.1 containing obfuscated stealer and backdoor functionality. The attack vector involved takeover of a dormant maintainer account through an expired email domain. The malware fingerprints host environments, enumerates and reads local files including SSH keys, cloud credentials, database configurations, and various developer secrets. Collected data is compressed into a gzip archive and exfiltrated via DNS TXT queries to attacker-controlled infrastructure disguised as legitimate Azure domains. The payload targets over 100 file patterns across macOS and Linux systems, focusing on developer credentials from AWS, Azure, GCP, Kubernetes, Docker, npm, GitHub, and numerous other services. The malicious code executes during CommonJS module loading, forking a detached child process to perform credential harvesting while avoiding detection through obfuscation and DNS-based covert channels.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e | — | 2026-05-20 | |
| FileHash-SHA256 | 78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981 | — | 2026-05-20 | |
| FileHash-SHA256 | 96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144 | — | 2026-05-20 | |
| FileHash-SHA256 | bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301 | — | 2026-05-20 | |
| FileHash-SHA256 | c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea | — | 2026-05-20 | |
| IPv4 | 37.16.75.69 | — | 2026-05-20 | |
| URL | http://sh.azurestaticprovider.net:443 | — | 2026-05-20 | |
| domain | atlantis-software.net | — | 2026-05-20 | |
| domain | child.channel | — | 2026-05-20 | |
| hostname | sh.azurestaticprovider.net | — | 2026-05-20 |
References (1)