Fake Corepack Website Delivers Infostealer and Proxyware to Developers

· Original article ↗

Summary

A fake Corepack site targets developers with downloads that install an infostealer and proxyware, while a separate path delivers adware-style software. Node.js contributors warned users, and OpenJS says the ISP was given 24 hours to address the abuse.

Key points

  • The domain corepack[.]org impersonates Corepack, exploiting its removal from Node.js 25 to attract developers searching for downloads.
  • The site's main download redirects to an OpenShield page and delivers vpnsetup_d9gfqvs3dsic73fcvi90.exe, which installs an infostealer and persistent Apprunner component.
  • Analysis found access to browser-profile data and stored SSH keys, host and process discovery, shell execution, and run-key persistence.
  • OpenShield also secretly enrolls affected machines as proxy exit nodes for third-party traffic, a practice known as proxyjacking.
  • A separate click path delivers OperaGXSetup.exe through an affiliate or malvertising redirect chain and was flagged for trojan activity.
  • Node.js maintainers marked the site's links dangerous. OpenJS reported that the ISP had been notified and would take action if the abuse was not addressed within 24 hours.
  • Corepack is an npm package, not a standalone Windows installer; the article recommends installing it from the npm registry or the official repository.

Article Details

Attack Vectors
  • The fake corepack[.]org site impersonates Corepack and offers executable downloads to developers seeking the tool.
  • The site's “Download Free” path redirects visitors to an OpenShield landing page and downloads a purported free VPN installer that, when executed, drops an infostealer and proxyware.
  • A separate click path uses a malvertising or affiliate redirect chain and a fake “Your File Download Is Ready” page to deliver OperaGXSetup.exe.
Defensive Notes
  • Treat downloads from corepack[.]org as malicious; Corepack has no official Windows installer or official website at that domain.
  • Install Corepack from the npm registry with npm install -g corepack or follow the official nodejs/corepack repository instructions.
  • Verify that a developer-tool download comes from an official project source before running it.

Indicators of compromise

TypeIndicatorContext
DOMAINaifpleasurebeh[.]orgListed as phishing and malware-delivery infrastructure associated with the fake Corepack site.
DOMAINbeadpie[.]xyzListed as phishing and malware-delivery infrastructure associated with the fake Corepack site.
DOMAINcorepack[.]orgFake Corepack site identified as phishing and malware-delivery infrastructure.
DOMAINghabovethec[.]infoListed as phishing and malware-delivery infrastructure associated with the fake Corepack site.
DOMAINmoonlighthathel[.]orgListed as phishing and malware-delivery infrastructure associated with the fake Corepack site.
DOMAINukankingwithea[.]comListed as phishing and malware-delivery infrastructure associated with the fake Corepack site.
DOMAINyakteam[.]xyzListed as phishing and malware-delivery infrastructure associated with the fake Corepack site.
HOSTNAMEnostop[.]go2cloud[.]orgListed as phishing and malware-delivery infrastructure associated with the fake Corepack site.

MITRE ATT&CK

Malware

Products

Industries

Related Articles