Three Malicious NPM Packages Target Developers’ Login Credentials
ID: ee57b823-f3c9-57d4-bca4-cbb2024985af
STIX ID: report--ee57b823-f3c9-57d4-bca4-cbb2024985af
Feed Name: GBHackers
Threat Score
Zscaler ThreatLabz discovered three typosquatted npm packages (bitcoin-main-lib, bitcoin-lib-js, bip40) that installed NodeCordRAT, a Discord-based remote access trojan which persisted via PM2 and exfiltrated developer-focused secrets (Chrome credentials, .env API tokens, MetaMask keys); the packages amassed ~3,400 downloads before removal and the report includes MD5 IOCs and recommended mitigations for supply‑chain hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
