Fake Corepack Website Delivers Infostealer and Proxyware to Developers

Summary
A fake Corepack site targets developers with downloads that install an infostealer and proxyware, while a separate path delivers adware-style software. Node.js contributors warned users, and OpenJS says the ISP was given 24 hours to address the abuse.
Key points
- The domain corepack[.]org impersonates Corepack, exploiting its removal from Node.js 25 to attract developers searching for downloads.
- The site's main download redirects to an OpenShield page and delivers vpnsetup_d9gfqvs3dsic73fcvi90.exe, which installs an infostealer and persistent Apprunner component.
- Analysis found access to browser-profile data and stored SSH keys, host and process discovery, shell execution, and run-key persistence.
- OpenShield also secretly enrolls affected machines as proxy exit nodes for third-party traffic, a practice known as proxyjacking.
- A separate click path delivers OperaGXSetup.exe through an affiliate or malvertising redirect chain and was flagged for trojan activity.
- Node.js maintainers marked the site's links dangerous. OpenJS reported that the ISP had been notified and would take action if the abuse was not addressed within 24 hours.
- Corepack is an npm package, not a standalone Windows installer; the article recommends installing it from the npm registry or the official repository.
Article Details
- Attack Vectors
- The fake corepack[.]org site impersonates Corepack and offers executable downloads to developers seeking the tool.
- The site's “Download Free” path redirects visitors to an OpenShield landing page and downloads a purported free VPN installer that, when executed, drops an infostealer and proxyware.
- A separate click path uses a malvertising or affiliate redirect chain and a fake “Your File Download Is Ready” page to deliver OperaGXSetup.exe.
- Defensive Notes
- Treat downloads from corepack[.]org as malicious; Corepack has no official Windows installer or official website at that domain.
- Install Corepack from the npm registry with npm install -g corepack or follow the official nodejs/corepack repository instructions.
- Verify that a developer-tool download comes from an official project source before running it.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | aifpleasurebeh[.]org | Listed as phishing and malware-delivery infrastructure associated with the fake Corepack site. |
| DOMAIN | beadpie[.]xyz | Listed as phishing and malware-delivery infrastructure associated with the fake Corepack site. |
| DOMAIN | corepack[.]org | Fake Corepack site identified as phishing and malware-delivery infrastructure. |
| DOMAIN | ghabovethec[.]info | Listed as phishing and malware-delivery infrastructure associated with the fake Corepack site. |
| DOMAIN | moonlighthathel[.]org | Listed as phishing and malware-delivery infrastructure associated with the fake Corepack site. |
| DOMAIN | ukankingwithea[.]com | Listed as phishing and malware-delivery infrastructure associated with the fake Corepack site. |
| DOMAIN | yakteam[.]xyz | Listed as phishing and malware-delivery infrastructure associated with the fake Corepack site. |
| HOSTNAME | nostop[.]go2cloud[.]org | Listed as phishing and malware-delivery infrastructure associated with the fake Corepack site. |
MITRE ATT&CK
T1057 · Process DiscoveryDynamic analysis confirmed process discovery after execution.T1059.001 · PowerShellDynamic analysis confirmed PowerShell execution by the payload.T1059.003 · Windows Command ShellDynamic analysis confirmed command-shell execution by the payload.T1082 · System Information DiscoveryDynamic analysis confirmed host discovery after execution.T1204.002 · Malicious FileThe fake Corepack site offers executable downloads whose malicious behavior occurs when a visitor runs the installer.T1547.001 · Registry Run Keys / Startup FolderDynamic analysis confirmed Run-key persistence for the installed payload.T1552.004 · Private KeysDynamic analysis confirmed access to stored SSH keys.T1555.003 · Credentials from Web BrowsersDynamic analysis confirmed access to browser-profile data.
Malware
Products
CorepackA website at corepack[.]org is impersonating Corepack, the Node.js tool for managing package managers, and using that identity to push malware to developers who land on the page looking for a download. The site hasNode.jsA website at corepack[.]org is impersonating Corepack, the Node.js tool for managing package managers, and using that identity to push malware to developers who land on the page looking for a download. The site has