Popular node-ipc npm package compromised to steal credentials
BleepingComputer [Unofficial]
May 15, 2026
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. [...]
Discussion in the ATmosphere