Discord Controlled NodeCordRAT Steals Chrome Data via NPM Packages
ID: ca744924-2ffb-555d-bce9-c74148d97bca
STIX ID: report--ca744924-2ffb-555d-bce9-c74148d97bca
Feed Name: HackRead
Zscaler ThreatLabz uncovered a malicious supply-chain campaign on NPM where three packages (bip40, bitcoin-lib-js, bitcoin-main-lib) impersonating bitcoinjs libraries delivered a Remote Access Trojan called NodeCordRAT. The attacker chained packages so installing two of them pulled in the payload (bip40), and the RAT uses Discord as a C2 channel with commands to execute shell commands, capture screenshots, and exfiltrate files; it specifically targets Chrome credentials, MetaMask seed phrases, API secrets and .env files. Although the packages have been removed from NPM, thousands of downloads mean many users and developers could already be compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
