Skip to main content

Fake Corepack Site Distributes Infostealer and Proxyware to Developers

0
Medium
Published: 07/25/2026 (07/25/2026, 07:54:44 UTC)
Source: AlienVault OTX General

Description

A fraudulent website impersonating Corepack, the Node.js package manager tool, is distributing malware to developers. The attackers exploit timing around Corepack's removal from Node.js bundling, targeting developers searching for installation instructions. The site offers Windows executables that deliver OpenShield infostealer and proxyware, enrolling victim machines in bandwidth-sharing networks without consent. The payload steals browser credentials, SSH keys, establishes persistence, and routes third-party traffic through compromised systems. An alternative download path delivers adware and trojan components disguised as OperaGX installer. The site features AI-generated content with obvious errors, including confusing Yarn package manager with textile crafts. The domain has been reported to registrars for takedown after community members identified the threat.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:45:01 UTC

Technical Analysis

This threat involves a typosquatting and phishing campaign using a fake website impersonating Corepack, a Node.js package manager tool. The attackers exploit timing around Corepack's removal from Node.js bundling to lure developers seeking installation instructions. The malicious site distributes Windows executables that install OpenShield infostealer and proxyware, which steal sensitive data such as browser credentials and SSH keys, maintain persistence, and enroll victim machines in bandwidth-sharing networks without consent. Additionally, an alternative download path delivers adware and trojan components masquerading as the OperaGX installer. The site features AI-generated content with noticeable errors, indicating a fraudulent source. The domain has been reported to registrars for takedown following community identification of the threat.

Potential Impact

The malware steals sensitive information including browser credentials and SSH keys, potentially compromising developer accounts and systems. It establishes persistence on infected machines and enrolls them in proxyware networks, which can degrade system performance and implicate victims in unauthorized third-party traffic routing. The presence of adware and trojan components further increases the risk of system compromise and unwanted software installation.

Defensive Guidance

The fraudulent domain has been reported to registrars for takedown, which is the primary mitigation step. Developers should avoid downloading Corepack or related tools from unofficial or suspicious websites. Verify official sources for installation instructions and downloads. There is no patch or fix applicable as this is a social engineering and malware distribution threat rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-proxyware"]
Pulse Id
6a646bc49938f4fb7a0a02f2

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincorepack.org
domainyakteam.xyz

Url

ValueDescriptionCopy
urlhttp://freevpn.win/lps/gbox-lp/index.html
urlhttp://openshield.canatrace.com/download-free-can/

Threat ID: 6a6711ac9c2644c7f8aca654

Added to database: 07/27/2026, 08:07:08 UTC

Last enriched: 07/31/2026, 12:45:01 UTC

Last updated: 09/10/2026, 05:29:11 UTC

Views: 209

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses