Fake Corepack Tool Site Exploits Developers with Malware
A fake website posing as a source for the Corepack toolset has been targeting Node.js developers with malware. Corepack, initially bundled with Node.js from version 16.9.0, was discontinued by the Node.js Technical Steering Committee in 2025. The fake site, Corepack.org, has been active since early 2026, offering a malicious executable download. This installer deploys an infostealer that accesses browser data and SSH keys, and enrolls the machine in a bandwidth-sharing scheme known as proxyjacking. The site also misleads users with a fake 'your file is ready' page, installing a disguised Opera GX setup file. Following reports from the developer community, the hosting provider has taken down the site, which now returns a 404 error.