HomeinetStealer Backdoor Discovered in 3 Versions of Node-IPC

Stealer Backdoor Discovered in 3 Versions of Node-IPC

Cybersecurity researchers are sounding the alarm over what has been described as a 'Stealer Backdoor' in newly released versions of node-ipc. According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious: node-ipc@9.1.6, node-ipc@9.2.3 , and node-ipc@12.0.1. Initial analysis shows that these versions contain stealer/backdoor behavior with camouflaged code.

See also: cPanel vulnerability used to distribute Filemanager Backdoor

Stealer Backdoor
Stealer Backdoor Discovered in 3 Versions of Node-IPC

The malware appears to recognize the host environment, enumerate and read local files, compress and parse the collected data, wrap the payload in a cryptographic shell, and attempt to extract data via a network endpoint selected via DNS/address logic.

StepSecurity noted that the heavily camouflaged payload is triggered when the package is required during execution, attempting to export a broad set of developer and cloud secrets to an external command and control (C2) server. This includes 90 categories of credentials, including Amazon Web Services, Google Cloud, Microsoft Azure, SSH keys, Kubernetes tokens, GitHub CLI configs , Claude AI and Kiro IDE settings , Terraform status , database passwords, shell history, and more.

The collected data is compressed into a GZIP file and transmitted to the domain 'sh.azurestaticprovider[.]net'. The three releases were published by an account named 'atiertant', which is not related to the original author of the package, 'riaevangelist'. Although ' atiertant ' appears in the maintainers list, the account has no previous history of releases related to the node-ipc package.

The package's previous update was in August 2024. The fact that the inactive, highly downloaded package was compromised after a 21-month period suggests that either 'atiertant''s credentials were recently compromised, or the account was specifically added as a maintainer to publish the malicious releases.

Notably, the activity does not rely on any npm lifecycle hooks such as preinstall, install or postinstall scripts, but instead adds the malicious payload as an Immediately Executable Function Expression (IIFE) at the end of 'node-ipc.cjs'. This causes the malware to execute independently every time require('node-ipc').

See also: New Python Backdoor uses Tunneling to steal credentials

Stealer Backdoor Discovered in 3 Versions of Node-IPC
Stealer Backdoor Discovered in 3 Versions of Node-IPC

The payload performs a SHA-256 fingerprint check and compares it to a hardcoded hash assembled from eight camouflaged table pieces embedded in the code, before proceeding to system enumeration and overall credential collection.

StepSecurity researcher Sai Likhith said this means that version 12.0.1 is completely inert on any machine whose main module path does not have a hash to the target value. The attacker knows exactly which project or developer is being targeted and has pre-computed the hash of their entry point before publishing. Versions 9.x do not have this gateway and will execute the full payload on any system that loads them.

The malware also incorporates a second extraction channel in addition to issuing an HTTPS POST to the fake Azure domain containing the compressed stolen data.

This involves encoding pieces of the file as a DNS TXT record after replacing the DNS resolver with Google Public DNS to bypass local DNS-based security checks. StepSecurity explained that it first resolves sh.azurestaticprovider.net using 1.1.1.1 (primary) or 8.8.8.8 (alternate) to obtain the C2 IP, and then redirects the resolver directly to the C2 IP for all outbound queries.

Connecting directly to the C2 DNS sink is a notable anti-detection technique. Because the export queries never touch public DNS resolvers, there is no observable activity in the public DNS records. Organizations that rely solely on DNS logging through corporate resolvers would not see this traffic. This is not the first time that an npm package has incorporated malicious functionality.

See also: WordPress: Backdoor detected in Quick Page/Post Redirect plugin

Stealer Backdoor Discovered in 3 Versions of Node-IPC
Stealer Backdoor Discovered in 3 Versions of Node-IPC

In March 2022, the package maintainer intentionally introduced a destructive capability in versions 10.1.1 and 10.1.2 by replacing files.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS