Back to Blog
high severity May 14, 2026 · scope unconfirmed

Malicious node-ipc npm Versions Steal Credentials

Three versions of the popular node-ipc package (9.1.6, 9.2.3, 12.0.1) were published to npm on May 14 with a credential-stealing backdoor. The malware exfiltrates sensitive files via DNS and impacted developers using the package, which has millions of weekly downloads.

⚠ Were you affected?
Free email scanner — we check your address against 15.4B+ leaked records in 15 seconds.
Run free scan →
Malicious node-ipc npm Versions Steal Credentials
Data exposed:
  • credentials
  • ssh-keys
  • env-files
  • cloud-credentials

Three versions of the widely used node-ipc npm package were published on May 14, 2026, each containing a credential-stealing backdoor that exfiltrates sensitive files through DNS queries.

Public reporting indicates the compromised releases — versions 9.1.6, 9.2.3, and 12.0.1 — were uploaded to the npm registry that day. The malicious code targeted developers by scanning for and transmitting credentials, SSH keys, environment files, and cloud credentials. The package maintains millions of weekly downloads, meaning any developer or organization incorporating it into build pipelines or applications during the brief window of compromise faced immediate risk of credential exposure. Industry research from sources such as DoxxScan™ continuous monitoring indicates that credential leaks of this nature frequently appear in subsequent breach datasets within weeks.

This incident matters for executives and high-net-worth families because many maintain personal development environments, home labs, or oversee technology teams that rely on open-source dependencies. A single compromised package can expose SSH keys used to access corporate infrastructure, cloud credentials tied to family office accounts, or environment files containing API tokens for personal services. Once exfiltrated, these credentials enable account takeovers that extend far beyond the original developer workstation.

The doxxing and identity-chain implications are particularly acute. Stolen credentials rarely remain isolated; they serve as entry points for broader reconnaissance. Attackers use leaked emails, usernames, or SSH-associated identities to correlate additional records across platforms, mapping digital handles back to real-world identities, addresses, and family members. What begins as a developer supply-chain breach can cascade into personal doxxing, especially when credentials are reused across professional and personal accounts or when children’s gaming profiles share household infrastructure.

What to do

  • Run a DoxxScan to map every link between your handles, emails, phone numbers, and real-world identity, including any developer credentials that may have surfaced.
  • Enable continuous DoxxScan monitoring across 15B+ breach records and 100+ platforms so the next exposure of your data is identified and addressed within hours rather than months.
  • Rotate every password and SSH key used on systems that incorporated node-ipc versions 9.1.6, 9.2.3, or 12.0.1, then replace them with unique credentials and enforce 2FA through an authenticator app on all affected services.
  • Cover the entire household with DoxxScan family protection, which extends to dependents and children’s gaming accounts that often chain back to the same addresses, emails, or reused credentials.
  • For executives and family offices, layer on hands-on remediation specialists who can execute targeted takedown requests across data brokers and underground forums where stolen credentials surface.

Credential theft through supply-chain attacks will remain a persistent threat as long as developers and organizations continue to rely on third-party packages without isolated build environments. Executives and high-net-worth families should treat every breach as the start of a potential identity chain rather than an isolated event. DoxxScan by GalaxyWarden delivers continuous monitoring across 15B+ breach records and 100+ platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and family coverage that includes children’s gaming accounts — capabilities that directly counter the cascading risks illustrated by this node-ipc incident.

Source: https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/

Why this isn’t just another breach checker

A breach leaks your credentials. Then hackers chain those credentials to your address, family, phone, and employer using public broker sites. We’re the only tool built around that chain.

Free checker Tells you the breach happened. End of story. You’re still on 800+ broker sites.
$129+/yr Broker-removal services scrub the address but don’t see the breach — next leak re-exposes you.
GalaxyWarden Maps the chain. Cleans both halves. $19 one-shot. Closed loop.

⚠ Were you in this breach?

Free email scanner. We check your address against 15.4B+ leaked records in 15 seconds — then show you the $19 cleanup that removes you from the broker sites aggregating leaked data.

Check my email — free →
Close the chain attack

Both halves of the chain, cleaned once.

A breach put your credentials in 15.4B+ leaked records. Hackers chain that data to your address on 800+ broker sites. GalaxyWarden closes both halves for $19 once — no subscription required.

Clean both halves — $19 →
Free breach scan + 800+ broker letters + 30-day proof · one payment, no subscription
W Warden Plus — ongoing monitoring $9.99/mo
Warden Plus ($9.99/mo or $99/yr): weekly re-scans, breach alerts, AI Concierge, auto re-files on relisted brokers.