Node-ipc NPM packages infected with stealer

Socket.dev has yet another NPM package compromise, in this case the node-ipc packages.

Affected versions:

Initial access appears to be email domain takeover from a dormant maintainer.

Assuming the npm account recovery email for atiertant was indeed hosted on atlantis-software[.]net , the new domain owner was then able to trigger a standard npm password reset, receive the reset email at a mailbox under their control, and gain publish rights without ever compromising any of the maintainer’s own infrastructure

Indicators of Compromise

Value Type Description
96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144 SHA256 node-ipc.cjs
449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e SHA256 node-ipc-9.1.6.tgz
c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea SHA266 node-ipc-9.2.3.tgz
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981 SHA256 node-ipc-12.0.1.tar.gz
sh[.]azurestaticprovider[.]net Domain Bootstrap resolver
bt[.]node[.]js Domain Exfiltration domain
37.16[.]75.69 IPv4 Boostrap IP

In addition to these indicators, a common exfil pattern was observed in longer domains.

xh.<machineHex>.<transferId>.<headerSig>.<chunkIndex>.<hexHeaderChunk>.bt[.]node[.]js
xd.<machineHex>.<transferId>.<bodySig>.<chunkIndex>.<hexBodyChunk>.bt[.]node[.]js
xf.<machineHex>.<transferId>.<footerSig>.0.<hexFooterJson>.bt[.]node[.]js
1 Like

DNSDB_RRSet__.azurestaticprovider.net_ANY_Limit_5000_20260514_212828.csv (1000 Bytes)

iris-pe-export-2026-05-14T17_30_27-04_00.csv (7.7 KB)

this one’s minty fresh, just registered today.

Hey for those who are unfamiliar, what is an “IRIS PE export?”

Credit to JR at Nymbl for the fast report.

2 Likes

Ah sorry - export from Iris Investigate (domain data platform from my employer, DomainTools)

Aggregated csv of domain details like whois, TLS cert, MX, IP, etc

1 Like