Back to Feed
Threat IntelligenceJul 24, 2026

Fake Corepack Site Distributes Infostealer and Proxyware to Developers

Fake Corepack site impersonates Node.js tool to distribute infostealer and proxyware.

Summary

A malicious website impersonating the Node.js Corepack tool is distributing malware to developers. The fake site, corepack[.]org, lures developers seeking Corepack after its removal from Node.js, offering executable downloads that install an infostealer and enroll machines in a proxy network. A secondary download path delivers adware and trojan activity.

Full text

Research/Security NewsLarge-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation CampaignA large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.By Kirill Boychenko - Jul 22, 2026

Indicators of Compromise

  • domain — corepack[.]org
  • domain — openshield[.]canatrace[.]com
  • domain — freevpn[.]win
  • domain — moonlighthathel[.]org
  • domain — aifpleasurebeh[.]org
  • domain — ghabovethec[.]info
  • domain — ukankingwithea[.]com
  • domain — beadpie[.]xyz
  • domain — yakteam[.]xyz
  • domain — nostop[.]go2cloud[.]org

Entities

Corepack (product)Node.js (technology)OpenShield (product)npm (technology)Yarn (technology)pnpm (technology)