logo

Discord Controlled NodeCordRAT Steals Chrome Data via NPM Packages

ID: ca744924-2ffb-555d-bce9-c74148d97bca

STIX ID: report--ca744924-2ffb-555d-bce9-c74148d97bca

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Zscaler ThreatLabz uncovered a malicious supply-chain campaign on NPM where three packages (bip40, bitcoin-lib-js, bitcoin-main-lib) impersonating bitcoinjs libraries delivered a Remote Access Trojan called NodeCordRAT. The attacker chained packages so installing two of them pulled in the payload (bip40), and the RAT uses Discord as a C2 channel with commands to execute shell commands, capture screenshots, and exfiltrate files; it specifically targets Chrome credentials, MetaMask seed phrases, API secrets and .env files. Although the packages have been removed from NPM, thousands of downloads mean many users and developers could already be compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.