惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
M
MIT News - Artificial intelligence
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
有赞技术团队
有赞技术团队
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog
美团技术团队
F
Fortinet All Blogs
I
Intezer
IT之家
IT之家
T
Threat Research - Cisco Blogs
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Know Your Adversary
Know Your Adversary
P
Proofpoint News Feed
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
AWS News Blog
AWS News Blog
P
Palo Alto Networks Blog
S
Securelist
L
LINUX DO - 热门话题
Security Archives - TechRepublic
Security Archives - TechRepublic
N
Netflix TechBlog - Medium
TaoSecurity Blog
TaoSecurity Blog
Scott Helme
Scott Helme
Hugging Face - Blog
Hugging Face - Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Project Zero
Project Zero
U
Unit 42
博客园_首页
博客园 - 司徒正美
S
Security Affairs
V
V2EX
T
Threatpost
T
Tailwind CSS Blog
GbyAI
GbyAI
O
OpenAI News
K
Kaspersky official blog
Y
Y Combinator Blog
宝玉的分享
宝玉的分享
H
Hacker News: Front Page
V2EX - 技术
V2EX - 技术
Security Latest
Security Latest

Socket

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr... Introducing Manifest Alerts - Socket GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ... Socket for Linear Is Now Available - Socket US Government Forces Anthropic to Pull Claude Fable Days After Launch 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic Andrew Becherer Joins Socket as Chief Information Security Officer Socket Partners with Replit to Block Malicious Packages in AI-Powered Development npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems pnpm 11.5 Adds Support for Recognizing npm Staged Publishes pnpm 11.5 Adds Support for Recognizing npm Staged Publishes Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Famous Chollima Targets PHP Developers Through Compromised Packagist Package Famous Chollima Targets PHP Developers Through Compromised Packagist Package Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io Laravel Lang Compromised with RCE Backdoor Across 700+ Versions Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects AI Has Taken Over Open Source npm Invalidates Granular Access Tokens as Mini Shai-Hulud Sweeps the Registry Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit Socket raises $60M Series C at $1B valuation led by Thrive Capital to secure AI-driven software development Socket Raises $60M Series C at a $1B Valuation to Help Enterprises Build Securely With AI Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor Active Supply Chain Attack Compromises @antv Packages on npm Popular node-ipc npm Package Infected with Credential Stealer TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks Packagist Urges Immediate Composer Update After GitHub Actions Token Leak GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government Socket Named to Rising in Cyber 2026 List of Top Cybersecurity Startups TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack fsnotify Maintainer Dispute Sparks Supply Chain Concerns Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape 5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies PyPI Fixes High-Severity Access Control Issues Found in Security Audit Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack lightning PyPI Package Compromised in Supply Chain Attack Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables SAP CAP npm Packages Hit by Supply Chain Attack Socket Has Acquired Secure Annex 73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations Introducing Reachability for PHP Introducing Data Exports Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions Introducing Organization Notifications in Socket Introducing Reports: An Extensible Reporting Framework for Socket Data Socket for Jira Is Now Available Socket Named Top Sales Organization by RepVue NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets Socket Selected for OpenAI's Cybersecurity Grant Program Feross on the 10 Minutes or Less Podcast: Nobody Reads the Code 108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure Node.js Drops Bug Bounty Rewards After Funding Dries Up The Hidden Blast Radius of the Axios Compromise
Fake Corepack Site Distributes Infostealer and Proxyware to ...
Kirill Boychenko · 2026-07-24 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

A website at corepack[.]org is impersonating Corepack, the Node.js tool for managing package managers, and using that identity to push malware to developers who land on the page looking for a download. The site has existed in some form since early 2026 as a low-quality, apparently AI-generated imitation, but it recently started serving executable downloads. Socket's Threat Research team analyzed the site and confirmed it as a developer-targeted phishing and impersonation operation that drops an infostealer and enrolls victims' machines in a bandwidth-sharing proxy network.

Corepack is not distributed as a Windows installer, and the real project has no official website at corepack.org. Any download offered there should be treated as malicious.

Corepack's Removal From Node.js Creates an Opening#

Corepack is an npm package that lets developers manage package managers like Yarn and pnpm and pin a specific version per project. It shipped as an experimental feature bundled with Node.js starting in version 16.9.0.

In 2025, the Node.js Technical Steering Committee voted to stop distributing Corepack with future releases. It remains available in Node.js 24 and earlier, and Node.js 25 stopped bundling it. Developers who still want Corepack now install it themselves, most commonly from the npm registry.

The attackers are exploiting that transition. Developers searching for how to get Corepack after its removal from Node.js are the exact audience most likely to click a top search result that promises a download. In a Node.js issue tracking the domain, one contributor reported corepack.org showing up as the second result when searching for "corepack" on DuckDuckGo.

The Download Delivers an Infostealer and Proxyware#

Clicking "Download Free" on the site redirects the visitor to an OpenShield landing page and downloads a file named vpnsetup_d9gfqvs3dsic73fcvi90.exe, presented as a free VPN client. The tool has nothing to do with Corepack.

When executed, the installer drops OpenShield along with a persistent Apprunner component. Socket classifies the payload as an infostealer. Dynamic analysis confirmed:

  • Access to browser-profile data and stored SSH keys
  • Host and process discovery
  • PowerShell and command-shell execution
  • Run-key persistence to survive reboots

OpenShield also enrolls the system in bandwidth sharing for third-party data-scraping traffic, effectively turning the machine into a proxy exit node. Hidden bandwidth-sharing installs of this kind are known as proxyjacking, and security vendors classify the clients as proxyware or riskware because the person running the machine has no visibility into what traffic routes through their connection.

A Second Path Delivers Adware and Trojan Activity#

A different click path on the same site enters a malvertising or affiliate redirect chain and displays a fake "Your File Download Is Ready" page. Clicking through downloads OperaGXSetup.exe. This branch is best described as deceptive adware-style software delivery, and the overall detonation was also flagged as trojan activity.

Two distinct delivery paths from a single fake domain point to a monetization setup that pays out through more than one channel: an infostealer and proxy enrollment on one side, affiliate or adware installs on the other.

The Site Appears to Be AI-Generated#

The impersonation is sloppy in ways that point to automated content generation with no understanding of the subject. The site's FAQ reads as LLM-generated, and in at least one answer it confuses the Yarn package manager with yarn the textile craft, responding to a question about "yarn bombing" as if the tool were related to knitting and crochet street art. The download link in the header is misspelled "Downlaod," and one advertised download archive did not exist when contributors checked it. The site gives no indication of who created it.

This is the same low-effort, high-volume impersonation pattern we've seen for years across the ecosystem, where lookalike domains and typosquats for trusted developer tools are spun up quickly and cheaply, then wired to a malware or affiliate backend.

Community Response and Takedown Efforts#

Node.js contributors flagged corepack.org in issue #803 on the nodejs/corepack repository, opened in March 2026. At the time, the site was only a poor, outdated informational page with no downloads, and a maintainer initially closed the issue as out of scope since the domain is not controlled by the project or the Node.js organization. The concern that it could be preparation for a supply chain attack was raised early and taken to the OpenJS Foundation, along with a possible trademark and copyright question over the Corepack name.

The issue was reopened once the site began offering downloads. Maintainers pinned it, marked a duplicate report, and warned that links on the site should be considered dangerous. A developer has reported the domain to the registrar through its abuse contact, and the situation now more clearly meets the criteria for anti-abuse action than it did when the site carried no downloads.

How to Get Corepack Safely#

Corepack is an npm package, not a standalone application, and there is no official installer at corepack.org. Install it from the npm registry with npm install -g corepack, or follow the instructions in the official nodejs/corepack repository. Treat any developer tool offered as a downloadable .exe from an unfamiliar domain as suspect, and confirm you are on an official project source before running anything.

Indicators of Compromise#

Files:

  • vpnsetup_d9gfqvs3dsic73fcvi90[.]exe
  • OperaGXSetup[.]exe

Phishing and malware-delivery infrastructure:

  • corepack[.]org
  • openshield[.]canatrace[.]com/download-free-can/
  • freevpn[.]win/lps/gbox-lp/index[.]html
  • moonlighthathel[.]org
  • aifpleasurebeh[.]org
  • ghabovethec[.]info
  • ukankingwithea[.]com
  • beadpie[.]xyz
  • yakteam[.]xyz
  • nostop[.]go2cloud[.]org