<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I am sure you&#x27;re shocked to hear about another NPM compromise.]]></title><description><![CDATA[<p>I am sure you're shocked to hear about another NPM compromise.</p><p>This one was because a maintainer let their email domain expire!</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://discourse.ifin.network/t/node-ipc-npm-packages-infected-with-stealer/454" title="Node-ipc NPM packages infected with stealer">
<img src="https://discourse.ifin.network/uploads/default/original/1X/f7b28d9aff4b3c69e392f1464b9e350b476adc55.png" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://discourse.ifin.network/t/node-ipc-npm-packages-infected-with-stealer/454">
Node-ipc NPM packages infected with stealer
</a>
</h5>
<p class="card-text line-clamp-3">Socket.dev has yet another NPM package compromise, in this case the node-ipc packages. 


Affected versions: 


node-ipc@9.1.6
node-ipc@9.2.3
node-ipc@12.0.1


Initial access appears to be email domain takeover from a do…</p>
</div>
<a href="https://discourse.ifin.network/t/node-ipc-npm-packages-infected-with-stealer/454" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://discourse.ifin.network/uploads/default/optimized/1X/ea367a05f4a0d090bf61d140dc84f744c9ab9bf0_2_32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />





<p class="d-inline-block text-truncate mb-0">IFIN <span class="text-secondary">(discourse.ifin.network)</span></p>
</a>
</div><p></p><p><a href="https://infosec.exchange/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a> <a href="https://infosec.exchange/tags/ThreatIntelligence" rel="tag">#<span>ThreatIntelligence</span></a> <a href="https://infosec.exchange/tags/IFIN" rel="tag">#<span>IFIN</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/65dad437-d587-415c-8353-2f8705d8f8e0/i-am-sure-you-re-shocked-to-hear-about-another-npm-compromise.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 06:18:42 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/65dad437-d587-415c-8353-2f8705d8f8e0.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 14 May 2026 22:20:47 GMT</pubDate><ttl>60</ttl></channel></rss>