What's Happening?
A fake website posing as a source for the Corepack toolset has been targeting Node.js developers with malware. Corepack, initially bundled with Node.js from version 16.9.0, was discontinued by the Node.js Technical Steering Committee in 2025. Exploiting
this, threat actors created a malicious site, Corepack.org, which appears as a top search result for the tool's name. The site offers an executable download that installs an infostealer capable of accessing browser data and SSH keys, and also enrolls the victim's machine in a proxyjacking scheme. This practice allows the machine's internet connection to be used as an exit node for other traffic, without the owner's knowledge. The malicious site has since been taken down following community reports and an abuse notification to the hosting provider.
Why It's Important?
This incident highlights the ongoing risks in software supply chains, particularly for developers seeking discontinued tools. The use of proxyjacking and infostealers poses significant security threats, potentially compromising sensitive data and network integrity. For developers, this underscores the importance of verifying sources and using official channels for software downloads. The broader tech community must remain vigilant against such threats, as they can lead to data breaches and unauthorized network usage, impacting both individual developers and larger organizations.











