logo

Three Malicious NPM Packages Target Developers’ Login Credentials

ID: ee57b823-f3c9-57d4-bca4-cbb2024985af

STIX ID: report--ee57b823-f3c9-57d4-bca4-cbb2024985af

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Zscaler ThreatLabz discovered three typosquatted npm packages (bitcoin-main-lib, bitcoin-lib-js, bip40) that installed NodeCordRAT, a Discord-based remote access trojan which persisted via PM2 and exfiltrated developer-focused secrets (Chrome credentials, .env API tokens, MetaMask keys); the packages amassed ~3,400 downloads before removal and the report includes MD5 IOCs and recommended mitigations for supply‑chain hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.