Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
AI-summarised brief · reviewed before publication
Cybersecurity researchers discovered malicious activity in three versions of the node-ipc npm package, specifically node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1, which contain obfuscated stealer/backdoor behavior, targeting developer secrets and cloud credentials, with the malware exfiltrating data to an external command-and-control server, affecting 90 categories of credentials, including major cloud providers and development tools, in a sophisticated attack.
💡 Why It Matters
- · The attack's precision targeting and use of a hardcoded hash to filter victims suggest a highly targeted campaign, potentially indicating a sophisticated adversary with specific interests, and the fact that the malware can evade detection by only executing on specific systems.