logo

Typosquatting campaign delivers r77 rootkit via npm

ID: 33e5295a-c1c6-5c4d-b068-01f84cfa51d2

STIX ID: report--33e5295a-c1c6-5c4d-b068-01f84cfa51d2

Feed Name: ReversingLabs Blog

Threat Score
72/100

Date Published: 2023-10-04

Date Updated: 2026-04-29

Author: [email protected] (Lucija Valentić)

...
...

ReversingLabs identified a typosquatting npm package, "node-hide-console-windows" (one-letter variant of a legitimate module), that downloaded a DiscordRAT 2.0 executable which can create per-victim Discord channels, execute commands (including disabling defenses) and launch the r77 rootkit to hide processes and paths; later versions also fetched a PyInstaller Blank-Grabber infostealer. The report documents analysis results, extracted Discord bot token and guild ID, lists IOCs, and warns that open-source malware and typosquatting on public repositories amplify software supply chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.