node-ipc dormant-maintainer takeover via expired email domain
On 2026-05-14 three malicious node-ipc releases (9.1.6, 9.2.3, 12.0.1) were published from a dormant maintainer account atiertant. The attacker re-registered the expired atlantis-software.net domain on 2026-05-07 and used npm's password-reset flow to seize publish rights. The payload fires on every require("node-ipc") (no lifecycle hook) and exfiltrates 90+ credential categories via DNS TXT queries. 12.0.1 was tagged latest, so any unpinned install during the ~60-second window pulled the backdoor. ~822K weekly downloads.
Versions named here: 9.1.6, 9.2.3, 12.0.1