Socket.dev has yet another NPM package compromise, in this case the node-ipc packages.
Affected versions:
Initial access appears to be email domain takeover from a dormant maintainer.
Assuming the npm account recovery email for
atiertantwas indeed hosted onatlantis-software[.]net, the new domain owner was then able to trigger a standard npm password reset, receive the reset email at a mailbox under their control, and gain publish rights without ever compromising any of the maintainer’s own infrastructure
Indicators of Compromise
| Value | Type | Description |
|---|---|---|
96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144 |
SHA256 | node-ipc.cjs |
449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e |
SHA256 | node-ipc-9.1.6.tgz |
c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea |
SHA266 | node-ipc-9.2.3.tgz |
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981 |
SHA256 | node-ipc-12.0.1.tar.gz |
sh[.]azurestaticprovider[.]net |
Domain | Bootstrap resolver |
bt[.]node[.]js |
Domain | Exfiltration domain |
37.16[.]75.69 |
IPv4 | Boostrap IP |
In addition to these indicators, a common exfil pattern was observed in longer domains.
xh.<machineHex>.<transferId>.<headerSig>.<chunkIndex>.<hexHeaderChunk>.bt[.]node[.]js
xd.<machineHex>.<transferId>.<bodySig>.<chunkIndex>.<hexBodyChunk>.bt[.]node[.]js
xf.<machineHex>.<transferId>.<footerSig>.0.<hexFooterJson>.bt[.]node[.]js