Fake Corepack Site Distributes Infostealer and Proxyware to Developers
Blog post from Socket
A fraudulent website impersonating Corepack, a Node.js tool for managing package managers, has been identified as distributing malware to unsuspecting developers. The site, corepack.org, which emerged around 2026, uses AI-generated content to deceive visitors into downloading a malicious executable disguised as a free VPN client. This executable includes an infostealer and proxyware, compromising users' systems by accessing sensitive data and enrolling them in a bandwidth-sharing network. Additionally, the site offers a deceptive adware installer, suggesting a multifaceted monetization strategy. This impersonation pattern reflects a broader trend of low-effort, high-volume attacks exploiting lookalike domains. The Node.js community has flagged the site, and efforts for its takedown are underway. Developers are advised to obtain Corepack through the npm registry and to remain cautious of executable downloads from untrusted sources.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.