The good news is there's already a patch. The bad news is that the fix isn't available for all Linux distributions yet.
Attackers performed an email takeover attack on a dormant maintainer account and published new node-ipc versions containing ...