MEDIUMSupply Chain
Global

Popular node-ipc npm package compromised to steal credentials

·Source: BleepingComputer

Updated:

Executive Summary

Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. [...]

Analysis

Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. [...]
Source Attribution

Originally published by BleepingComputer on May 15, 2026.

Related Threats