Threat reportSupply ChainTL-2026-0518

Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) — Credential Stealer with DNS Exfiltration via sh.azurestaticprovider.net

criticalMONITORING

Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) (TL-2026-0518), also tracked as node-ipc supply chain compromise 2026, is a critical-severity supply-chain compromise, first published 2026-05-15. It has no confirmed attribution, affects node-ipc maintainers (npm) node-ipc, maps to 34 MITRE ATT&CK techniques (T1005, T1027, T1027.013), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
34MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0518

Threat ID
TL-2026-0518
Also known as
node-ipc supply chain compromise 2026, atiertant takeover, azurestaticprovider stealer
Severity
CRITICAL
Status
MONITORING
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software-development, devops, cloud, ci-cd, open-source-ecosystem
Target regions
Global
Detection rules
9
Indicators of compromise
25

How Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) works

Three malicious node-ipc npm versions (9.1.6, 9.2.3, 12.0.1) were published on 2026-05-14 containing a backdoored CommonJS entrypoint that activates on require() rather than via npm lifecycle scripts. The payload forks a detached child process, harvests cloud, SCM, SSH, Kubernetes, Terraform, and developer secrets into a gzipped tar archive, then exfiltrates the data over DNS TXT queries to the lookalike domain sh.azurestaticprovider.net (suffix bt.node.js). The compromise is attributed to takeover of the dormant maintainer account 'atiertant' via an expired recovery email domain (atlantis-software.net).

## Overview

On 2026-05-14 between 14:25 and 14:26 UTC, three new versions of the popular node-ipc npm package — 9.1.6, 9.2.3, and 12.0.1 — were published containing a credential-stealing backdoor. node-ipc has approximately 822,000 weekly downloads and is a transitive dependency of widely deployed tooling including the Vue CLI, making this one of the highest-impact npm supply chain incidents of 2026 to date. The malicious releases were withdrawn within hours, but any CI/CD pipeline, developer workstation, or production build that resolved to one of the affected versions during the publication window must be considered compromised until cleared by credential rotation.

## Attack Vector

Independent analyses by Datadog Security Labs, Socket, SafeDep and StepSecurity converge on dormant-maintainer account takeover as the most plausible initial vector. The package was published from the 'atiertant' npm account, which had been inactive for years. The recovery email associated with the account used the domain atlantis-software.net, which had expired and become available for re-registration. By acquiring the expired domain, the adversary was able to receive npm password-reset email and seize control of the publish credentials without bypassing 2FA on a live mailbox. This pattern matches a class of npm supply-chain incidents documented since 2022 against unmaintained but still-widely-depended-on packages.

## Payload Activation

Unlike the more common 'preinstall' / 'postinstall' lifecycle script abuse pattern, the node-ipc payload does not run at install time. Instead, the malicious code is embedded in the CommonJS entrypoint shipped as node-ipc.cjs (SHA-256 96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144). It executes the first time any code calls require('node-ipc') in the consuming Node.js process. This significantly reduces detectability: package managers' install-time security scanners that focus on lifecycle script execution will see nothing, and the malicious behaviour only manifests inside the application runtime. A hash gate inside the payload decides at load time whether to fully replace module.exports with a benign-looking shim or to augment exports with a function named __ntRun, presumably to defeat detection in test environments.

## Execution and Process Behaviour

Once activated, the loader uses setImmediate to schedule the malicious work outside the synchronous import path, then forks a detached Node.js child process with stdio set to 'ignore'. The child sets the environment variable __ntw=1 to mark itself, drops into a per-invocation working directory of the form <tmpdir>/nt-<pid>/, and proceeds with host fingerprinting and credential harvesting. Detaching the child prevents the parent application from blocking on the malicious work and allows the stealer to outlive short-lived processes such as test runners or build steps. A tarball timestamp anomaly — the embedded mtime resolves to 'Oct 26 1985' (the Back to the Future date) — is used as a self-marker by the actor and is a high-fidelity indicator for forensic triage.

## Credential Harvesting Targets

The stealer enumerates the home directory and project directory for a wide set of high-value secret stores: AWS credentials (~/.aws/credentials), Azure access tokens (~/.azure/accessTokens.json), Google Cloud application default credentials (~/.config/gcloud/application_default_credentials.json), Oracle Cloud configuration (~/.oci/config), npm authentication tokens (.npmrc and ~/.npmrc), git credentials (~/.git-credentials and embedded credentials in .git/config), GitHub CLI hosts (~/.config/gh/hosts.yml), SSH private keys (~/.ssh/id_rsa, ~/.ssh/id_ed25519), Kubernetes kubeconfig (~/.kube/config), in-cluster service account tokens (/var/run/secrets/kubernetes.io/serviceaccount/token), generic .env and .env.production files, Rails-style database configuration (config/database.yml), Terraform variable files (terraform.tfvars), WordPress configuration (wp-config.php), the macOS Keychain database, Firefox key databases, Linux GNOME keyrings and KWallet files, and Microsoft Teams LevelDB stores. The selection is consistent with an adversary monetising stolen secrets across cloud takeover, source-code theft, npm package republishing, and Teams session hijack scenarios.

## Collection and Encoding

Harvested files are written into the per-invocation working directory and packed into a gzipped tar archive named <machineHex>.tar.gz where machineHex is a hex-encoded host fingerprint. The archive is then wrapped in a custom envelope: a SHA-256-derived keystream (seeded from the embedded key 'qZ8pL3vNxR9wKmTyHbVcFgDsJaEoUi') is XORed against the gzipped data, and a truncated 12-hex-character HMAC-SHA256 signature is appended for integrity. The result is hex-encoded for transport. A custom 16-character alphabet '0123456789GHJKMP' is used to fragment chunks into DNS-label-safe lengths.

## DNS Exfiltration Channel

Exfiltration uses DNS TXT queries to sh.azurestaticprovider.net under the suffix bt.node.js. Header records use the prefix xh. and carry up to 63 characters of metadata (machine ID, chunk count, payload size). Data records use the prefixes xd. and xf. and carry 31 characters per chunk before hex encoding doubles their length. Queries are batched up to 160 at a time using Promise.all with an 8000 ms timeout. Choosing DNS as the channel routes around most outbound HTTPS proxies, gives the adversary stealth against firewall log review (DNS volume to one apex domain is rarely investigated), and resolves through whatever recursive resolver the host is configured to use. The lookalike apex domain — sh.azurestaticprovider.net versus the legitimate Azure Static Web Apps domain azurestaticapps.net — is engineered to be missed in eyeball reviews of DNS logs. The authoritative IP at the time of analysis is 37.16.75.69.

## Defensive Posture

Any Node.js host that resolved to node-ipc 9.1.6, 9.2.3, or 12.0.1 between 14:25 UTC on 2026-05-14 and the takedown of the malicious tarballs must be treated as compromised. Required actions: (1) audit npm lockfiles, CI artifact caches, and container base images for the affected versions and SHA-256 hashes; (2) rotate every credential listed under credential targets that was reachable from the affected hosts (AWS access keys, Azure tokens, GCP credentials, GitHub PATs, npm tokens, SSH keys, Kubernetes kubeconfig contexts, Terraform variables, .env values); (3) sinkhole or block resolution of sh.azurestaticprovider.net and the IP 37.16.75.69 at the resolver and egress firewall; (4) hunt historical DNS logs for any TXT queries matching the patterns xh.<...>.bt.node.js, xd.<...>.bt.node.js, and xf.<...>.bt.node.js; (5) rebuild any container images or VM templates produced from a poisoned build; (6) review npm registry audit logs for unexpected publishes from accounts in the same dormant-maintainer cohort.

MITRE ATT&CK techniques used in TL-2026-0518

Collection

T1005 Data from Local System; T1560.001 Archive Collected Data: Archive via Utility; T1560.003 Archive Collected Data: Archive via Custom Method

Defense Evasion

T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048.003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1204 User Execution

Command and Control

T1071.004 Application Layer Protocol: DNS; T1132.002 Data Encoding: Non-Standard Encoding; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1573.001 Encrypted Channel: Symmetric Cryptography

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1526 Cloud Service Discovery

Initial Access

T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain; T1199 Trusted Relationship

Credential Access

T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys; T1552.005 Unsecured Credentials: Cloud Instance Metadata API; T1555 Credentials from Password Stores; T1555.001 Credentials from Password Stores: Keychain; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Persistence

T1554 Compromise Host Software Binary

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1586 Compromise Accounts; T1586.002 Compromise Accounts: Email Accounts; T1588.001 Obtain Capabilities: Malware

Affected products and versions in Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)

  • node-ipc maintainers (npm) — node-ipc
    Vulnerable versions: 9.1.6; 9.2.3; 12.0.1
    Fixed in: any clean release reverted post-incident; pin to <= 9.2.2 or >= 12.0.2 with verified integrity hash
  • Vue.js — @vue/cli (transitive consumers of node-ipc)
    Vulnerable versions: any installation that resolved a poisoned node-ipc version during the 2026-05-14 window
    Fixed in: any installation with a regenerated lockfile that excludes 9.1.6, 9.2.3, 12.0.1

Remediation for Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)

Patches

  • Upgrade node-ipc to a clean release (>= 12.0.2 or any version reverted by maintainers post-incident) and verify the integrity hash matches a clean publish
  • Revert package-lock.json entries pointing at the malicious tarball integrity hashes

Immediate actions

  • Block resolution of sh.azurestaticprovider.net at recursive DNS resolvers and egress firewalls
  • Block outbound traffic to 37.16.75.69 at perimeter firewalls
  • Audit lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml) for node-ipc 9.1.6, 9.2.3, or 12.0.1
  • Audit npm cache and CI/CD artifact stores for the four malicious tarball SHA-256 hashes
  • Quarantine any developer workstations or CI runners that resolved to a poisoned version during the 2026-05-14 publication window
  • Treat all credentials accessible from poisoned hosts as compromised — see long_term rotation list

Workarounds

  • Pin node-ipc to a specific known-good version (e.g. 9.2.2 or earlier) in package.json with the exact integrity hash recorded in a clean lockfile
  • Temporarily replace node-ipc with an internal fork or alternative IPC library if a clean upstream release is not yet available
  • Block outbound DNS to sh.azurestaticprovider.net and egress traffic to 37.16.75.69 to neutralise live infections while remediation is in progress

Longer-term hardening

  • Rotate AWS access keys, Azure access tokens, GCP credentials, OCI config, GitHub PATs, SSH keys, npm tokens, Kubernetes kubeconfig contexts, and any .env / terraform.tfvars values reachable from poisoned hosts
  • Rebuild any container images or VM templates produced from a build that included a poisoned node-ipc
  • Pin transitive Node.js dependencies via lockfile integrity hashes and require lockfile review on every PR
  • Adopt an internal npm proxy (Verdaccio, JFrog, Nexus) with a delay window or human review on new releases of high-impact packages
  • Monitor DNS query patterns for anomalous TXT-heavy traffic to single apex domains, especially Azure / AWS / GCP lookalikes
  • Inventory dormant maintainer accounts in critical dependencies and request npm to enforce stronger reactivation controls
  • Deploy npm security tooling (Socket, Snyk, Datadog SCA, Phylum) in PR gates to flag suspicious package versions before they reach lockfiles

Weaknesses (CWE) in Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)

CWE-506, CWE-829, CWE-494, CWE-522, CWE-798

Timeline of Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)

  • Independent researchers attribute the compromise to a takeover of the 'atiertant' npm maintainer account via re-registration of the expired recovery email domain atlantis-software.net.
  • The Hacker News, SafeDep, and StepSecurity publish corroborating analyses confirming the supply chain compromise and the credential-targeting payload.
  • Verified IOCs disclosed: domain sh.azurestaticprovider.net, IP 37.16.75.69, DNS suffix bt.node.js, four tarball/file SHA-256 hashes.
  • Datadog Security Labs and Socket Security publish independent technical analyses of the backdoored releases, including SHA-256 hashes, IOC list, and DNS exfiltration mechanism.
  • Malicious node-ipc 9.1.6, 9.2.3, and 12.0.1 published to npm by the dormant 'atiertant' maintainer account between 14:25 and 14:26 UTC.
  • Threadlinqs Intelligence publishes consolidated TL-2026-0518 advisory with MITRE ATT&CK mapping, full IOC set, and detection guidance.
  • As of 2026-05-29, the acute incident is contained: the three malicious node-ipc versions (9.1.6/9.2.3/12.0.1) were unpublished within ~2 hours on 2026-05-14 and clean versions (9.1.5, 12.0.0) are available. But the financially-motivated actor is unattributed/uncaught, the C2 (sh.azurestaticprovider.net / 37.16.75.69) was never confirmed taken down, and exposed hosts still need credential rotation.

Sources cited for Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)

Detection coverage for TL-2026-0518

As of 2026-05-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0518 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats