Malicious NPM Packages Deliver NodeCordRAT
ID: 5c10a943-59f5-55e4-a4a1-f368aca368b0
STIX ID: report--5c10a943-59f5-55e4-a4a1-f368aca368b0
Feed Name: Zscaler Security Research Blog
Threat Score
This report describes NodeCordRAT being distributed through malicious npm packages (for example, 'bip40') that serve as required dependencies for legitimate-seeming wrapper packages; the package's postinstall.cjs script resolves and launches the RAT under PM2 in detached mode to achieve runtime persistence and automatic execution without user interaction, with excerpts of package.json and postinstall.cjs included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
