Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
swapupdate.in May 15, 2026

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

AI-summarised brief · reviewed before publication

Cybersecurity researchers discovered malicious activity in three versions of the node-ipc npm package, specifically node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1, which contain obfuscated stealer/backdoor behavior, targeting developer secrets and cloud credentials, with the malware exfiltrating data to an external command-and-control server, affecting 90 categories of credentials, including major cloud providers and development tools, in a sophisticated attack.

💡 Why It Matters

  • · The attack's precision targeting and use of a hardcoded hash to filter victims suggest a highly targeted campaign, potentially indicating a sophisticated adversary with specific interests, and the fact that the malware can evade detection by only executing on specific systems.