logo

Tsundere Botnet Abusing Popular Node.js and Cryptocurrency Packages to Attack Windows, Linux, and macOS Users

ID: f8de304c-a4f1-5c95-a885-568b08d96a0d

STIX ID: report--f8de304c-a4f1-5c95-a885-568b08d96a0d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-11-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Tsundere is a sophisticated, multi-platform botnet first observed in October 2024 and reported by researchers in mid-2025; attackers distributed it via 287 typosquatted npm packages and disguised game installers, targeting Windows (and initially Linux/macOS) users. The botnet achieves persistence with pm2 and registry entries, retrieves rotating C2 addresses from Ethereum smart contracts via public RPCs, establishes encrypted WebSocket communications, and executes dynamic JavaScript commands—making it resilient to IP-based blocking and enabling a criminal marketplace for renting or extending bot functionality.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.