ended5월 19일· 1 sources

Credential Stealer Spreads Through npm: 314 Packages Compromised via node-ipc Takeover

node-ipc 계정 탈취, 314개 npm 패키지에 자격증명 탈취 악성코드 확산

Why it matters

A maintainer account takeover of node-ipc allowed attackers to inject an 80KB obfuscated credential stealer into 314 npm packages, targeting over 100 sensitive file types including SSH keys. This demonstrates how a single compromised account in a foundational library can cascade through hundreds of downstream dependencies, exposing millions of developers and their credentials to attackers.

1
Sources
+0
24h
Growth
4d
Active
npmnode-ipccredential stealersupply chainaccount takeover

Sources

Related Issues