Node-ipc supply chain attack targets crypto devs

Source Cryptopolitan

Three poisoned versions of node-ipc went live on the npm registry on May 14, according to SlowMist. Attackers hijacked a dormant maintainer account and pushed code designed to siphon developer credentials, private keys, exchange API secrets, the works, straight out of .env files.

node-ipc is a popular Node.js package that lets different programs talk to each other on the same machine, or sometimes across a network.

SlowMist catches the breach

Blockchain security firm, SlowMist, spotted the breach through their MistEye threat intel system.

Versions 9.1.6, 9.2.3, and 12.0.1

MistEye found three malicious versions including:

  • Version 9.1.6.
  • Version 9.2.3.
  • Version 12.0.1.

All of the above verions carried the same obfuscated 80 KB payload.

Node-ipc handles inter-process communication in Node.js. It basically helps Node.js programs send messages back and forth. Over 822,000 people download it each week.

Node-ipc is used all over the crypto space. It’s used in the tools developers use to build dApps, in the systems that automatically test and deploy code (CI/CD), and in everyday developer tools.

Each infected version had the same hidden malicious code bolted onto it. The moment any program loaded node-ipc, the code ran automatically.

Attackers hijack npm maintainer account, steal crypto keys.
Screenshot from MistyEye showing malicious node-ipc packages. Source: SlowMist via X.

Researchers at StepSecurity figured out how the attack happened. The original developer of node-ipc had an email address tied to the domain atlantis-software[.]net. However, the domain expired on January 10, 2025.

On May 7, 2026, the attacker bought the same domain through Namecheap, which gave them control of the developer’s old email. From there, they just hit “forgot password” on npm, reset it, and walked right in with full permission to publish new versions of node-ipc.

The real developer had no clue any of this was happening. The malicious versions stayed live for about two hours before removal.

The stealer looks for 90+ credential types

The embedded payload hunts for over 90 types of developer and cloud credentials. AWS tokens, Google Cloud and Azure secrets, SSH keys, Kubernetes configs, GitHub CLI tokens, all on the list.

For crypto devs, the malware specifically raids .env files. Those usually hold private keys, RPC node credentials, and exchange API secrets.

To sneak the stolen data out, the payload uses DNS tunneling. It basically hides the files inside normal-looking internet lookup requests. Most network security tools don’t catch that.

Security teams are saying any project that ran npm install or had auto-updated dependencies during that two hour window should assume compromise.

Immediate steps, per guidance from SlowMist:

  • Check lock files for node-ipc versions 9.1.6, 9.2.3, or 12.0.1.
  • Roll back to the last version you know is safe.
  • Change every credential that might have leaked.

Supply chain attacks on npm have become a regular thing in 2026. Crypto projects get hit harder than most because stolen logins can be turned into stolen money fast.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
MicroStrategy Shares are Performing Better than Bitcoin In 2026, But How?MicroStrategy stock is up nearly 3% at press time, trading above $137 as markets opened on March 9. Strategy just announced another 17,994 BTC purchase for $1.28 billion.The stock trades 57% lower ove
Author  Beincrypto
Mar 10, Tue
MicroStrategy stock is up nearly 3% at press time, trading above $137 as markets opened on March 9. Strategy just announced another 17,994 BTC purchase for $1.28 billion.The stock trades 57% lower ove
placeholder
What to Expect From NVIDIA Stock Price in April 2026?NVIDIA (NASDAQ: NVDA) stock price trades at $177.64 on the 2-day chart, up 5.31% over the past days but still down 6% year-to-date. April sits at a unique inflection for the stock. The Iran conflict c
Author  Beincrypto
Apr 08, Wed
NVIDIA (NASDAQ: NVDA) stock price trades at $177.64 on the 2-day chart, up 5.31% over the past days but still down 6% year-to-date. April sits at a unique inflection for the stock. The Iran conflict c
placeholder
3 Space Stocks To Watch Amid Elon Musk’s SpaceX IPO HypeA $1.75 trillion IPO is about to redefine which space stocks to watch this summer. SpaceX is closing in on the largest IPO ever. The public S-1 is due late May, with the listing slated for late June o
Author  Beincrypto
May 09, Sat
A $1.75 trillion IPO is about to redefine which space stocks to watch this summer. SpaceX is closing in on the largest IPO ever. The public S-1 is due late May, with the listing slated for late June o
placeholder
A Phone Call From Trump Just Earned Nvidia Stock a Potential 30% BoostNvidia (NVDA) stock price has rallied for seven consecutive sessions since the May 6 breakout, climbing to $227 on May 13. The move sits inside a 32% measured move setup, and the fundamental catalysts
Author  Beincrypto
May 14, Thu
Nvidia (NVDA) stock price has rallied for seven consecutive sessions since the May 6 breakout, climbing to $227 on May 13. The move sits inside a 32% measured move setup, and the fundamental catalysts
placeholder
Prediction markets weigh hardware flaws against Nvidia’s quarterly earnings streakInvestors are waiting for Nvidia’s results on May 20, but concerns about problems with its newest graphics cards are creating uncertainty about what the results will show. The chipmaker will report first-quarter fiscal 2027 earnings next week. Betting platforms tracking business outcomes expect strong results. On Polymarket, users price in about a 97% chance of...
Author  Cryptopolitan
Yesterday 02: 17
Investors are waiting for Nvidia’s results on May 20, but concerns about problems with its newest graphics cards are creating uncertainty about what the results will show. The chipmaker will report first-quarter fiscal 2027 earnings next week. Betting platforms tracking business outcomes expect strong results. On Polymarket, users price in about a 97% chance of...
goTop
quote