npm package report

Is node-ipc safe?

This package is in our known-malicious corpus. Details below.

Flagged as malicious

  • Protestware / Data Wiper, affects 10.1.1,10.1.2,9.2.2
cvss
9.8

how bad it is if exploited, out of 10

epss
4.3%

chance of exploitation in the next 30 days

xyz score
4.9

CyberXYZ composite, out of 10

fig. 01 — GHSA-97m3-w2cp-4xx6, the advisory selected below

// advisories

GHSA-97m3-w2cp-4xx6

CRITICALCVE-2022-23812

The package node-ipc versions 10.1.1 and 10.1.2 are vulnerable to embedded malicious code that was introduced by the maintainer. The malicious code was intended to overwrite arbitrary files dependent upon the geo-location of the user IP address. The maintainer removed the malicious code in version 10.1.3.

Affected
>= 10.1.1, < 10.1.3
Fixed in
10.1.3
Weakness
CWE-94
Published
2022-03-16
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:40 UTC. The most recent advisory here was published 2022-03-16. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is node-ipc safe? npm package security report | CyberXYZ