node-ipc npm package supply chain attack malware | MSSP Advisory

High
DateMay 15, 2026
📋Executive Summary
Attackers compromised the node-ipc npm package by registering an expired domain to hijack a maintainer account, publishing malicious versions 9.1.6, 9.2.3, and 12.0.1 that contain credential-stealing malware. The malware targets CI/CD tools, cloud services, Kubernetes, SSH credentials, and AI platforms. Node-ipc receives 700K weekly downloads and serves as a dependency for 424 other projects.
⚠️Why It Matters for MSSPs
Your automation tools likely consume npm packages that could pull in compromised dependencies like node-ipc, potentially exposing your RMM credentials and client access tokens stored in your environment. Every client running Node.js applications or CI/CD pipelines faces credential theft risk if they unknowingly installed these malicious versions, and you need to audit their environments immediately.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Supply Chain

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.