Skip to content
The Nexus
SECURITYMay 15 · 17:10 UTCBLEEPING COMPUTERBill Toulas

Popular node-ipc npm package compromised to steal credentials

Hackers have compromised the node-ipc npm package by injecting credential-stealing malware into its newly published versions, targeting npm in a supply chain attack. This attack aims to steal credentials from users of the popular inter-process communication package. The incident highlights a significant security risk for users relying on the package.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this