ended5월 19일· 1 sources
Credential Stealer Spreads Through npm: 314 Packages Compromised via node-ipc Takeover
node-ipc 계정 탈취, 314개 npm 패키지에 자격증명 탈취 악성코드 확산
Why it matters
A maintainer account takeover of node-ipc allowed attackers to inject an 80KB obfuscated credential stealer into 314 npm packages, targeting over 100 sensitive file types including SSH keys. This demonstrates how a single compromised account in a foundational library can cascade through hundreds of downstream dependencies, exposing millions of developers and their credentials to attackers.
1
Sources
+0
24h
—
Growth
4d
Active
npmnode-ipccredential stealersupply chainaccount takeover