Malicious node-ipc packages on npm exposed crypto and cloud credentials

According to SlowMist (blockchain security firm), three poisoned node-ipc versions were published on May 14 after a dormant maintainer account was hijacked, with the malware targeting .env secrets and using DNS tunneling (data exfiltration via DNS requests).

Summary

verifying reliability

Terms & Concepts

No specialized terms available for this topic.