Malicious node-ipc npm Versions Steal Credentials: What Was Reportedly Exposed & What To Do
Malicious versions of the node-ipc npm package that steal credentials, SSH keys, environment files, and cloud credentials were disclosed on May 14, 2026. Anyone who installed or used node-ipc recently should check their systems for the malicious versions and rotate any exposed credentials immediately.
The discovery of malicious versions of the node-ipc package on the npm registry illustrates the continued exposure of software supply chains to tampering. On May 14, 2026, three versions containing credential-stealing code were published and reached developers who rely on the package for inter-process communication tasks.
Incidents of this kind matter because the affected package records millions of weekly downloads and is incorporated into many development and production environments. When a widely used component is altered, the consequences can extend beyond the initial users to any systems that consume the tainted code.
What happened
Three versions of the node-ipc package—9.1.6, 9.2.3, and 12.0.1—were published to the npm registry on May 14, 2026, each containing a backdoor designed to steal credentials. The malicious code exfiltrates sensitive files over DNS. The number of people or organizations affected remains unknown, and no further technical details about the scope of the compromise have been disclosed.
How a breach like this happens
Supply-chain compromises involving open-source package registries often begin when an attacker gains the ability to publish updates under an established package name. Once the altered code is released, any automated build or installation process that pulls the latest version can incorporate the malicious functionality without immediate detection by downstream users.
The backdoor then operates within the runtime environment, searching for files that commonly contain authentication material and transmitting their contents through covert channels such as DNS queries. Because the package is invoked during normal application execution, the activity can blend with legitimate traffic until anomalous network behavior or credential misuse is noticed.
About Malicious node-ipc npm Versions Steal Credentials
node-ipc is a widely adopted JavaScript package that enables inter-process communication within Node.js applications. It is used in development tooling, server processes, and distributed systems where separate components need to exchange data reliably. Organizations across software development, cloud infrastructure, and enterprise IT routinely include such packages in their dependency trees.
A compromise at this layer is consequential because the package’s reach extends into environments that handle production secrets and infrastructure access. Developers who incorporated the affected versions introduced the credential-stealing behavior directly into their own codebases and any downstream systems that consumed those builds.
What data was at risk
The malicious versions targeted credentials, ssh-keys, env-files, and cloud-credentials. No inventory of specific files or accounts has been published, and the precise volume or sensitivity of data that may have been transmitted remains unconfirmed.
Projects that depend on node-ipc commonly store authentication tokens, private keys, and environment variables in locations the malware was designed to locate. Without additional disclosure, the exact contents that left any given environment cannot be verified from public information.
The real-world impact
Developers and organizations that installed the compromised versions face the possibility that authentication material was copied to external systems. This can lead to unauthorized access to repositories, cloud consoles, or internal networks if the stolen items are later used.
For the broader ecosystem, the incident underscores the difficulty of distinguishing legitimate updates from malicious ones when relying on automated dependency management. Organizations may need to audit recent builds, rotate credentials, and review network logs for unexpected DNS traffic patterns associated with the affected package versions.
If your data was in this claimed breach
Review dependency lockfiles and build histories to determine whether any of the three listed versions were installed. Rotate any credentials or keys that resided in files the malware was configured to target, and monitor authentication logs for unexpected access attempts.
Readers can run a free exposure scan of their email address against known breach data to check for prior appearances of their information in other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Brazilian IT Firm Service IT Breached by WorldLeaksNissan Discloses Employee Data Breach via Oracle PeopleSoft Zero-DayIcarus Group Steals Salesforce Data via Klue OAuth BreachAdditional Klue Supply-Chain Breach Victims IdentifiedLatest breaches
Read GalaxyWarden’s full analysis of the Malicious node-ipc npm Versions Steal Credentials →
Based on public reporting
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.