NodeCordRAT: The Trojan Hiding in NPM to Steal Crypto via Discord
ID: 87cd5b9a-b502-524e-bd3a-7d6193e13a50
STIX ID: report--87cd5b9a-b502-524e-bd3a-7d6193e13a50
Feed Name: securityonline.info
Zscaler ThreatLabz discovered NodeCordRAT, a supply-chain malware campaign delivered through three malicious npm packages (bitcoin-main-lib, bitcoin-lib-js, bip40) that impersonated bitcoinjs tools; the RAT uses postinstall scripts to collect Chrome login databases, MetaMask files, and .env secrets and uploads them via a hardcoded Discord bot to private channels, leveraging Discord’s API as C2 to evade detection. Developers are urged to verify library authenticity and exercise caution when importing packages related to cryptocurrency operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
