← heapsort
ARTICLE27

Malicious node-ipc Versions Target Cloud, AI Tool Credentials via Supply Chain Backdoor

DEV.to AIΒ·May 17, 2026

Malicious versions of the node-ipc npm package were found to contain stealer/backdoor payloads. The malware harvests credentials for AI tools and cloud services like AWS, Azure, and GCP, exfiltrating data via HTTPS and DNS.

Read original β†—