Back to Feed
Threat IntelligenceJul 24, 2026

Fake Corepack Site Distributes Infostealer and Proxyware to Developers

Fake Corepack site impersonates Node.js tool to distribute infostealer and proxyware.

Vendor Watch

Run Corepack?

Get an email when a reviewed story names Corepack, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

A malicious website impersonating the Node.js Corepack tool is distributing malware to developers. The fake site, corepack[.]org, lures developers seeking Corepack after its removal from Node.js, offering executable downloads that install an infostealer and enroll machines in a proxy network. A secondary download path delivers adware and trojan activity.

Full text

Research/Security NewsLarge-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation CampaignA large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.By Kirill Boychenko - Jul 22, 2026

Indicators of Compromise

  • domain — corepack[.]org
  • domain — openshield[.]canatrace[.]com
  • domain — freevpn[.]win
  • domain — moonlighthathel[.]org
  • domain — aifpleasurebeh[.]org
  • domain — ghabovethec[.]info
  • domain — ukankingwithea[.]com
  • domain — beadpie[.]xyz
  • domain — yakteam[.]xyz
  • domain — nostop[.]go2cloud[.]org

Entities

Corepack (product)Node.js (technology)OpenShield (product)npm (technology)Yarn (technology)pnpm (technology)