# Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) — Credential Stealer with DNS Exfiltration via sh.azurestaticprovider.net

> Three malicious node-ipc npm versions (9.1.6, 9.2.3, 12.0.1) were published on 2026-05-14 containing a backdoored CommonJS entrypoint that activates on require() rather than via npm lifecycle scripts. The payload forks a detached child process, harvests cloud, SCM, SSH, Kubernetes, Terraform, and developer secrets into a gzipped tar archive, then exfiltrates the data over DNS TXT queries to the lookalike domain sh.azurestaticprovider.net (suffix bt.node.js). The compromise is attributed to takeover of the dormant maintainer account 'atiertant' via an expired recovery email domain (atlantis-software.net).

- **Published:** 2026-05-15T12:00:00Z
- **Last reviewed:** 2026-05-15T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0518
- **ID:** TL-2026-0518
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

## Overview

On 2026-05-14 between 14:25 and 14:26 UTC, three new versions of the popular node-ipc npm package — 9.1.6, 9.2.3, and 12.0.1 — were published containing a credential-stealing backdoor. node-ipc has approximately 822,000 weekly downloads and is a transitive dependency of widely deployed tooling including the Vue CLI, making this one of the highest-impact npm supply chain incidents of 2026 to date. The malicious releases were withdrawn within hours, but any CI/CD pipeline, developer workstation, or production build that resolved to one of the affected versions during the publication window must be considered compromised until cleared by credential rotation.

## Attack Vector

Independent analyses by Datadog Security Labs, Socket, SafeDep and StepSecurity converge on dormant-maintainer account takeover as the most plausible initial vector. The package was published from the 'atiertant' npm account, which had been inactive for years. The recovery email associated with the account used the domain atlantis-software.net, which had expired and become available for re-registration. By acquiring the expired domain, the adversary was able to receive npm password-reset email and seize control of the publish credentials without bypassing 2FA on a live mailbox. This pattern matches a class of npm supply-chain incidents documented since 2022 against unmaintained but still-widely-depended-on packages.

## Payload Activation

Unlike the more common 'preinstall' / 'postinstall' lifecycle script abuse pattern, the node-ipc payload does not run at install time. Instead, the malicious code is embedded in the CommonJS entrypoint shipped as node-ipc.cjs (SHA-256 96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144). It executes the first time any code calls require('node-ipc') in the consuming Node.js process. This significantly reduces detectability: package managers' install-time security scanners that focus on lifecycle script execution will see nothing, and the malicious behaviour only manifests inside the application runtime. A hash gate inside the payload decides at load time whether to fully replace module.exports with a benign-looking shim or to augment exports with a function named __ntRun, presumably to defeat detection in test environments.

## Execution and Process Behaviour

Once activated, the loader uses setImmediate to schedule the malicious work outside the synchronous import path, then forks a detached Node.js child process with stdio set to 'ignore'. The child sets the environment variable __ntw=1 to mark itself, drops into a per-invocation working directory of the form <tmpdir>/nt-<pid>/, and proceeds with host fingerprinting and credential harvesting. Detaching the child prevents the parent application from blocking on the malicious work and allows the stealer to outlive short-lived processes such as test runners or build steps. A tarball timestamp anomaly — the embedded mtime resolves to 'Oct 26 1985' (the Back to the Future date) — is used as a self-marker by the actor and is a high-fidelity indicator for forensic triage.

## Credential Harvesting Targets

The stealer enumerates the home directory and project directory for a wide set of high-value secret stores: AWS credentials (~/.aws/credentials), Azure access tokens (~/.azure/accessTokens.json), Google Cloud application default credentials (~/.config/gcloud/application_default_credentials.json), Oracle Cloud configuration (~/.oci/config), npm authentication tokens (.npmrc and ~/.npmrc), git credentials (~/.git-credentials and embedded credentials in .git/config), GitHub CLI hosts (~/.config/gh/hosts.yml), SSH private keys (~/.ssh/id_rsa, ~/.ssh/id_ed25519), Kubernetes kubeconfig (~/.kube/config), in-cluster service account tokens (/var/run/secrets/kubernetes.io/serviceaccount/token), generic .env and .env.production files, Rails-style database configuration (config/database.yml), Terraform variable files (terraform.tfvars), WordPress configuration (wp-config.php), the macOS Keychain database, Firefox key databases, Linux GNOME keyrings and KWallet files, and Microsoft Teams LevelDB stores. The selection is consistent with an adversary monetising stolen secrets across cloud takeover, source-code theft, npm package republishing, and Teams session hijack scenarios.

## Collection and Encoding

Harvested files are written into the per-invocation working directory and packed into a gzipped tar archive named <machineHex>.tar.gz where machineHex is a hex-encoded host fingerprint. The archive is then wrapped in a custom envelope: a SHA-256-derived keystream (seeded from the embedded key 'qZ8pL3vNxR9wKmTyHbVcFgDsJaEoUi') is XORed against the gzipped data, and a truncated 12-hex-character HMAC-SHA256 signature is appended for integrity. The result is hex-encoded for transport. A custom 16-character alphabet '0123456789GHJKMP' is used to fragment chunks into DNS-label-safe lengths.

## DNS Exfiltration Channel

Exfiltration uses DNS TXT queries to sh.azurestaticprovider.net under the suffix bt.node.js. Header records use the prefix xh. and carry up to 63 characters of metadata (machine ID, chunk count, payload size). Data records use the prefixes xd. and xf. and carry 31 characters per chunk before hex encoding doubles their length. Queries are batched up to 160 at a time using Promise.all with an 8000 ms timeout. Choosing DNS as the channel routes around most outbound HTTPS proxies, gives the adversary stealth against firewall log review (DNS volume to one apex domain is rarely investigated), and resolves through whatever recursive resolver the host is configured to use. The lookalike apex domain — sh.azurestaticprovider.net versus the legitimate Azure Static Web Apps domain azurestaticapps.net — is engineered to be missed in eyeball reviews of DNS logs. The authoritative IP at the time of analysis is 37.16.75.69.

## Defensive Posture

Any Node.js host that resolved to node-ipc 9.1.6, 9.2.3, or 12.0.1 between 14:25 UTC on 2026-05-14 and the takedown of the malicious tarballs must be treated as compromised. Required actions: (1) audit npm lockfiles, CI artifact caches, and container base images for the affected versions and SHA-256 hashes; (2) rotate every credential listed under credential targets that was reachable from the affected hosts (AWS access keys, Azure tokens, GCP credentials, GitHub PATs, npm tokens, SSH keys, Kubernetes kubeconfig contexts, Terraform variables, .env values); (3) sinkhole or block resolution of sh.azurestaticprovider.net and the IP 37.16.75.69 at the resolver and egress firewall; (4) hunt historical DNS logs for any TXT queries matching the patterns xh.<...>.bt.node.js, xd.<...>.bt.node.js, and xf.<...>.bt.node.js; (5) rebuild any container images or VM templates produced from a poisoned build; (6) review npm registry audit logs for unexpected publishes from accounts in the same dormant-maintainer cohort.

## MITRE ATT&CK

- T1586 Compromise Accounts
- T1586.002 Compromise Accounts: Email Accounts
- T1583.001 Acquire Infrastructure: Domains
- T1588.001 Obtain Capabilities: Malware
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools
- T1199 Trusted Relationship
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1204 User Execution
- T1554 Compromise Host Software Binary
- T1027 Obfuscated Files or Information
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1036.005 Match Legitimate Resource Name or Location
- T1140 Deobfuscate/Decode Files or Information
- T1564 Hide Artifacts
- T1552.001 Unsecured Credentials: Credentials In Files
- T1552.004 Unsecured Credentials: Private Keys
- T1552.005 Unsecured Credentials: Cloud Instance Metadata API
- T1555 Credentials from Password Stores
- T1555.001 Credentials from Password Stores: Keychain
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1528 Steal Application Access Token
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1526 Cloud Service Discovery
- T1005 Data from Local System
- T1560.001 Archive Collected Data: Archive via Utility
- T1560.003 Archive Collected Data: Archive via Custom Method
- T1071.004 Application Layer Protocol: DNS
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1132.002 Data Encoding: Non-Standard Encoding
- T1568.002 Dynamic Resolution: Domain Generation Algorithms
- T1048.003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol
- T1041 Exfiltration Over C2 Channel

## Sources

- [Backdoored node-ipc npm releases steal developer credentials through DNS queries](https://securitylabs.datadoghq.com/articles/node-ipc-npm-malware-analysis/)
- [Popular node-ipc npm Package Infected with Credential Stealer](https://socket.dev/blog/node-ipc-package-compromised)
- [Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets](https://thehackernews.com/2026/05/stealer-backdoor-found-in-3-node-ipc.html)
- [Compromised node-ipc on npm: Credential Stealer via DNS Exfiltration](https://safedep.io/malicious-node-ipc-npm-compromise/)
- [Active Supply Chain Attack: Malicious node-ipc Versions Published to npm](https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack)
- [MITRE ATT&CK T1195.002 — Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK T1071.004 — Application Layer Protocol: DNS](https://attack.mitre.org/techniques/T1071/004/)
- [MITRE ATT&CK T1552.001 — Unsecured Credentials: Credentials In Files](https://attack.mitre.org/techniques/T1552/001/)
- [MITRE ATT&CK T1048.003 — Exfiltration Over Unencrypted Non-C2 Protocol](https://attack.mitre.org/techniques/T1048/003/)
- [CWE-506 — Embedded Malicious Code](https://cwe.mitre.org/data/definitions/506.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0518
