Skip to content
The Nexus
DossierENTITY

node-ipc

Coverage of node-ipc in the Nexus archive.

Earliest in view: May 14 · 17:22 UTCMost recent: Jun 23 · 00:17 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJun 23 · 00:17 UTCTHE REGISTER
    Sniff out stale AI override advice with this open source CLI

    The CVE Lite CLI, an open-source tool endorsed by OWASP, helps developers scan dependencies to mitigate software supply chain attacks. Its recent update includes override auditing to address transitive dependency vulnerabilities, such as those seen in the node-ipc package incident and Shai-hulud attacks. The tool identifies broken overrides in projects like Cal.com, which had 11 ineffective override entries.

  • SECURITYMay 15 · 17:10 UTCBLEEPING COMPUTER
    Popular node-ipc npm package compromised to steal credentials

    Hackers have compromised the node-ipc npm package by injecting credential-stealing malware into its newly published versions, targeting npm in a supply chain attack. This attack aims to steal credentials from users of the popular inter-process communication package. The incident highlights a significant security risk for users relying on the package.

  • SECURITYMay 14 · 17:22 UTCTHE HACKER NEWS
    Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

    Cybersecurity researchers found malicious activity in three versions of node-ipc, specifically [email protected], [email protected], and [email protected], which target developer secrets. The affected npm packages are part of the node-ipc library. This discovery raises concerns about the security of developer tools.