people · May 18, 2026
Snyk Publishes Advisory on Malicious node-ipc Versions Published to npm on May 14 2026
Share the canonical public link.
Snyk published a security advisory on May 15 2026 for malicious versions of the npm package node-ipc. On May 14 2026 at approximately 14:25 UTC, versions node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1 were published containing an obfuscated credential-stealing payload in the CommonJS bundle. The attack likely involved abuse of a legitimate npm maintainer account rather than CI/CD pipeline compromise, with the payload harvesting over 90 categories of credentials including cloud, SSH, Kubernetes, GitHub, and AI tool configurations before exfiltrating to attacker infrastructure. Snyk referenced its prior 2022 analysis of the node-ipc/peacenotwar incident and recommended using advisory SNYK-JS-NODEIPC-16697063 along with Snyk CLI and web UI for detection and remediation.