Threat IntelligenceJul 24, 2026
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
Fake Corepack site impersonates Node.js tool to distribute infostealer and proxyware.
Summary
A malicious website impersonating the Node.js Corepack tool is distributing malware to developers. The fake site, corepack[.]org, lures developers seeking Corepack after its removal from Node.js, offering executable downloads that install an infostealer and enroll machines in a proxy network. A secondary download path delivers adware and trojan activity.
Full text
Research/Security NewsLarge-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation CampaignA large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.By Kirill Boychenko - Jul 22, 2026
Indicators of Compromise
- domain — corepack[.]org
- domain — openshield[.]canatrace[.]com
- domain — freevpn[.]win
- domain — moonlighthathel[.]org
- domain — aifpleasurebeh[.]org
- domain — ghabovethec[.]info
- domain — ukankingwithea[.]com
- domain — beadpie[.]xyz
- domain — yakteam[.]xyz
- domain — nostop[.]go2cloud[.]org
Entities
Corepack (product)Node.js (technology)OpenShield (product)npm (technology)Yarn (technology)pnpm (technology)