Popular node-ipc npm Package Infected with Credential Stealer

Reported 20 May 2026 by otx · Severity: medium

A supply chain attack has compromised the node-ipc npm package, with malicious versions 9.1.6, 9.2.3, and 12.0.1 containing obfuscated stealer and backdoor functionality. The attack vector involved takeover of a dormant maintainer account through an expired email domain. The malw