logo

Malicious NPM Packages Deliver NodeCordRAT

ID: 8aa4cd7b-51f4-5db6-be5c-491a75f94768

STIX ID: report--8aa4cd7b-51f4-5db6-be5c-491a75f94768

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Satyam Singh (Associate Security Researcher)

...
...

Zscaler ThreatLabz discovered three malicious npm packages that deliver a Node.js remote access trojan called NodeCordRAT via a supply-chain typosquatting technique; the RAT uses PM2 for runtime persistence, Discord for C2, can execute shell commands, capture screenshots, and exfiltrate Chrome credentials, .env files, and MetaMask wallet data. The blog provides technical analysis, IOCs (package names and MD5 hashes), and MITRE ATT&CK mappings to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.