//pragmatic leaders

signal

Node.js dropped Corepack to avoid supply chain risk, but attackers exploited the gap

This shows the product decision to remove a bundled tool to reduce maintenance or risk can backfire if the ecosystem lacks a secure, official alternative, exposing users to supply chain attacks.

Frame 1 of 4

Fake Corepack tool site goes quiet after luring devs with malware

Node.js stopped bundling Corepack from version 25, leading attackers to create a fake Corepack.org site distributing malware to developers searching for the tool. Corepack was bundled experimentally with Node.js from version 16.9.0 but dropped entirely from Node.js 25 after a TSC vote. Attackers set up a fake Corepack.org site distributing malware, which appeared high in search results for Corepack downloads.