← Back to feed
Threat Actors & CampaignsEmerging1 sourceMay 14, 2026 · 00:00via Datadog Security Labs

Backdoored node-ipc npm releases steal developer credentials through DNS queries

Brief

An analysis of backdoored node-ipc npm releases that add an obfuscated credential collection and DNS exfiltration payload to the CommonJS entrypoint.

Read more on Datadog Security Labs