Threat reportSupply ChainTL-2026-0518
Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) — Credential Stealer with DNS Exfiltration via sh.azurestaticprovider.net
Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) (TL-2026-0518), also tracked as node-ipc supply chain compromise 2026, is a critical-severity supply-chain compromise, first published 2026-05-15. It has no confirmed attribution, affects node-ipc maintainers (npm) node-ipc, maps to 34 MITRE ATT&CK techniques (T1005, T1027, T1027.013), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 34MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-0518
- Threat ID
- TL-2026-0518
- Also known as
- node-ipc supply chain compromise 2026, atiertant takeover, azurestaticprovider stealer
- Severity
- CRITICAL
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, devops, cloud, ci-cd, open-source-ecosystem
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 25
How Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) works
Three malicious node-ipc npm versions (9.1.6, 9.2.3, 12.0.1) were published on 2026-05-14 containing a backdoored CommonJS entrypoint that activates on require() rather than via npm lifecycle scripts. The payload forks a detached child process, harvests cloud, SCM, SSH, Kubernetes, Terraform, and developer secrets into a gzipped tar archive, then exfiltrates the data over DNS TXT queries to the lookalike domain sh.azurestaticprovider.net (suffix bt.node.js). The compromise is attributed to takeover of the dormant maintainer account 'atiertant' via an expired recovery email domain (atlantis-software.net).
## Overview
On 2026-05-14 between 14:25 and 14:26 UTC, three new versions of the popular node-ipc npm package — 9.1.6, 9.2.3, and 12.0.1 — were published containing a credential-stealing backdoor. node-ipc has approximately 822,000 weekly downloads and is a transitive dependency of widely deployed tooling including the Vue CLI, making this one of the highest-impact npm supply chain incidents of 2026 to date. The malicious releases were withdrawn within hours, but any CI/CD pipeline, developer workstation, or production build that resolved to one of the affected versions during the publication window must be considered compromised until cleared by credential rotation.
## Attack Vector
Independent analyses by Datadog Security Labs, Socket, SafeDep and StepSecurity converge on dormant-maintainer account takeover as the most plausible initial vector. The package was published from the 'atiertant' npm account, which had been inactive for years. The recovery email associated with the account used the domain atlantis-software.net, which had expired and become available for re-registration. By acquiring the expired domain, the adversary was able to receive npm password-reset email and seize control of the publish credentials without bypassing 2FA on a live mailbox. This pattern matches a class of npm supply-chain incidents documented since 2022 against unmaintained but still-widely-depended-on packages.
## Payload Activation
Unlike the more common 'preinstall' / 'postinstall' lifecycle script abuse pattern, the node-ipc payload does not run at install time. Instead, the malicious code is embedded in the CommonJS entrypoint shipped as node-ipc.cjs (SHA-256 96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144). It executes the first time any code calls require('node-ipc') in the consuming Node.js process. This significantly reduces detectability: package managers' install-time security scanners that focus on lifecycle script execution will see nothing, and the malicious behaviour only manifests inside the application runtime. A hash gate inside the payload decides at load time whether to fully replace module.exports with a benign-looking shim or to augment exports with a function named __ntRun, presumably to defeat detection in test environments.
## Execution and Process Behaviour
Once activated, the loader uses setImmediate to schedule the malicious work outside the synchronous import path, then forks a detached Node.js child process with stdio set to 'ignore'. The child sets the environment variable __ntw=1 to mark itself, drops into a per-invocation working directory of the form <tmpdir>/nt-<pid>/, and proceeds with host fingerprinting and credential harvesting. Detaching the child prevents the parent application from blocking on the malicious work and allows the stealer to outlive short-lived processes such as test runners or build steps. A tarball timestamp anomaly — the embedded mtime resolves to 'Oct 26 1985' (the Back to the Future date) — is used as a self-marker by the actor and is a high-fidelity indicator for forensic triage.
## Credential Harvesting Targets
The stealer enumerates the home directory and project directory for a wide set of high-value secret stores: AWS credentials (~/.aws/credentials), Azure access tokens (~/.azure/accessTokens.json), Google Cloud application default credentials (~/.config/gcloud/application_default_credentials.json), Oracle Cloud configuration (~/.oci/config), npm authentication tokens (.npmrc and ~/.npmrc), git credentials (~/.git-credentials and embedded credentials in .git/config), GitHub CLI hosts (~/.config/gh/hosts.yml), SSH private keys (~/.ssh/id_rsa, ~/.ssh/id_ed25519), Kubernetes kubeconfig (~/.kube/config), in-cluster service account tokens (/var/run/secrets/kubernetes.io/serviceaccount/token), generic .env and .env.production files, Rails-style database configuration (config/database.yml), Terraform variable files (terraform.tfvars), WordPress configuration (wp-config.php), the macOS Keychain database, Firefox key databases, Linux GNOME keyrings and KWallet files, and Microsoft Teams LevelDB stores. The selection is consistent with an adversary monetising stolen secrets across cloud takeover, source-code theft, npm package republishing, and Teams session hijack scenarios.
## Collection and Encoding
Harvested files are written into the per-invocation working directory and packed into a gzipped tar archive named <machineHex>.tar.gz where machineHex is a hex-encoded host fingerprint. The archive is then wrapped in a custom envelope: a SHA-256-derived keystream (seeded from the embedded key 'qZ8pL3vNxR9wKmTyHbVcFgDsJaEoUi') is XORed against the gzipped data, and a truncated 12-hex-character HMAC-SHA256 signature is appended for integrity. The result is hex-encoded for transport. A custom 16-character alphabet '0123456789GHJKMP' is used to fragment chunks into DNS-label-safe lengths.
## DNS Exfiltration Channel
Exfiltration uses DNS TXT queries to sh.azurestaticprovider.net under the suffix bt.node.js. Header records use the prefix xh. and carry up to 63 characters of metadata (machine ID, chunk count, payload size). Data records use the prefixes xd. and xf. and carry 31 characters per chunk before hex encoding doubles their length. Queries are batched up to 160 at a time using Promise.all with an 8000 ms timeout. Choosing DNS as the channel routes around most outbound HTTPS proxies, gives the adversary stealth against firewall log review (DNS volume to one apex domain is rarely investigated), and resolves through whatever recursive resolver the host is configured to use. The lookalike apex domain — sh.azurestaticprovider.net versus the legitimate Azure Static Web Apps domain azurestaticapps.net — is engineered to be missed in eyeball reviews of DNS logs. The authoritative IP at the time of analysis is 37.16.75.69.
## Defensive Posture
Any Node.js host that resolved to node-ipc 9.1.6, 9.2.3, or 12.0.1 between 14:25 UTC on 2026-05-14 and the takedown of the malicious tarballs must be treated as compromised. Required actions: (1) audit npm lockfiles, CI artifact caches, and container base images for the affected versions and SHA-256 hashes; (2) rotate every credential listed under credential targets that was reachable from the affected hosts (AWS access keys, Azure tokens, GCP credentials, GitHub PATs, npm tokens, SSH keys, Kubernetes kubeconfig contexts, Terraform variables, .env values); (3) sinkhole or block resolution of sh.azurestaticprovider.net and the IP 37.16.75.69 at the resolver and egress firewall; (4) hunt historical DNS logs for any TXT queries matching the patterns xh.<...>.bt.node.js, xd.<...>.bt.node.js, and xf.<...>.bt.node.js; (5) rebuild any container images or VM templates produced from a poisoned build; (6) review npm registry audit logs for unexpected publishes from accounts in the same dormant-maintainer cohort.
MITRE ATT&CK techniques used in TL-2026-0518
Collection
T1005 Data from Local System; T1560.001 Archive Collected Data: Archive via Utility; T1560.003 Archive Collected Data: Archive via Custom Method
Defense Evasion
T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048.003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1204 User Execution
Command and Control
T1071.004 Application Layer Protocol: DNS; T1132.002 Data Encoding: Non-Standard Encoding; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1573.001 Encrypted Channel: Symmetric Cryptography
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1526 Cloud Service Discovery
Initial Access
T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain; T1199 Trusted Relationship
Credential Access
T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys; T1552.005 Unsecured Credentials: Cloud Instance Metadata API; T1555 Credentials from Password Stores; T1555.001 Credentials from Password Stores: Keychain; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Persistence
T1554 Compromise Host Software Binary
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1586 Compromise Accounts; T1586.002 Compromise Accounts: Email Accounts; T1588.001 Obtain Capabilities: Malware
Affected products and versions in Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)
- node-ipc maintainers (npm) — node-ipc
Vulnerable versions: 9.1.6; 9.2.3; 12.0.1
Fixed in: any clean release reverted post-incident; pin to <= 9.2.2 or >= 12.0.2 with verified integrity hash - Vue.js — @vue/cli (transitive consumers of node-ipc)
Vulnerable versions: any installation that resolved a poisoned node-ipc version during the 2026-05-14 window
Fixed in: any installation with a regenerated lockfile that excludes 9.1.6, 9.2.3, 12.0.1
Remediation for Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)
Patches
- Upgrade node-ipc to a clean release (>= 12.0.2 or any version reverted by maintainers post-incident) and verify the integrity hash matches a clean publish
- Revert package-lock.json entries pointing at the malicious tarball integrity hashes
Immediate actions
- Block resolution of sh.azurestaticprovider.net at recursive DNS resolvers and egress firewalls
- Block outbound traffic to 37.16.75.69 at perimeter firewalls
- Audit lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml) for node-ipc 9.1.6, 9.2.3, or 12.0.1
- Audit npm cache and CI/CD artifact stores for the four malicious tarball SHA-256 hashes
- Quarantine any developer workstations or CI runners that resolved to a poisoned version during the 2026-05-14 publication window
- Treat all credentials accessible from poisoned hosts as compromised — see long_term rotation list
Workarounds
- Pin node-ipc to a specific known-good version (e.g. 9.2.2 or earlier) in package.json with the exact integrity hash recorded in a clean lockfile
- Temporarily replace node-ipc with an internal fork or alternative IPC library if a clean upstream release is not yet available
- Block outbound DNS to sh.azurestaticprovider.net and egress traffic to 37.16.75.69 to neutralise live infections while remediation is in progress
Longer-term hardening
- Rotate AWS access keys, Azure access tokens, GCP credentials, OCI config, GitHub PATs, SSH keys, npm tokens, Kubernetes kubeconfig contexts, and any .env / terraform.tfvars values reachable from poisoned hosts
- Rebuild any container images or VM templates produced from a build that included a poisoned node-ipc
- Pin transitive Node.js dependencies via lockfile integrity hashes and require lockfile review on every PR
- Adopt an internal npm proxy (Verdaccio, JFrog, Nexus) with a delay window or human review on new releases of high-impact packages
- Monitor DNS query patterns for anomalous TXT-heavy traffic to single apex domains, especially Azure / AWS / GCP lookalikes
- Inventory dormant maintainer accounts in critical dependencies and request npm to enforce stronger reactivation controls
- Deploy npm security tooling (Socket, Snyk, Datadog SCA, Phylum) in PR gates to flag suspicious package versions before they reach lockfiles
Weaknesses (CWE) in Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)
Timeline of Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)
- Independent researchers attribute the compromise to a takeover of the 'atiertant' npm maintainer account via re-registration of the expired recovery email domain atlantis-software.net.
- The Hacker News, SafeDep, and StepSecurity publish corroborating analyses confirming the supply chain compromise and the credential-targeting payload.
- Verified IOCs disclosed: domain sh.azurestaticprovider.net, IP 37.16.75.69, DNS suffix bt.node.js, four tarball/file SHA-256 hashes.
- Datadog Security Labs and Socket Security publish independent technical analyses of the backdoored releases, including SHA-256 hashes, IOC list, and DNS exfiltration mechanism.
- Malicious node-ipc 9.1.6, 9.2.3, and 12.0.1 published to npm by the dormant 'atiertant' maintainer account between 14:25 and 14:26 UTC.
- Threadlinqs Intelligence publishes consolidated TL-2026-0518 advisory with MITRE ATT&CK mapping, full IOC set, and detection guidance.
- As of 2026-05-29, the acute incident is contained: the three malicious node-ipc versions (9.1.6/9.2.3/12.0.1) were unpublished within ~2 hours on 2026-05-14 and clean versions (9.1.5, 12.0.0) are available. But the financially-motivated actor is unattributed/uncaught, the C2 (sh.azurestaticprovider.net / 37.16.75.69) was never confirmed taken down, and exposed hosts still need credential rotation.
Sources cited for Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1)
- Backdoored node-ipc npm releases steal developer credentials through DNS queries
- Popular node-ipc npm Package Infected with Credential Stealer
- Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
- Compromised node-ipc on npm: Credential Stealer via DNS Exfiltration
- Active Supply Chain Attack: Malicious node-ipc Versions Published to npm
- MITRE ATT&CK T1195.002 — Compromise Software Supply Chain
- MITRE ATT&CK T1071.004 — Application Layer Protocol: DNS
- MITRE ATT&CK T1552.001 — Unsecured Credentials: Credentials In Files
- MITRE ATT&CK T1048.003 — Exfiltration Over Unencrypted Non-C2 Protocol
- CWE-506 — Embedded Malicious Code
Detection coverage for TL-2026-0518
As of 2026-05-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0518 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.