CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

NodeCordRAT Malware Delivered via Bitcoin-Themed npm Packages

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Researchers discovered three malicious npm packages—bitcoin-main-lib, bitcoin-lib-js, and bip40—that delivered a previously undocumented remote access trojan (RAT) named NodeCordRAT. The packages, uploaded by a user named "wenmoonx," were designed to steal Google Chrome credentials, API tokens, and cryptocurrency wallet seed phrases. NodeCordRAT uses Discord servers for command-and-control (C2) communications and was capable of executing arbitrary shell commands, taking screenshots, and exfiltrating files. The packages were taken down in November 2025.

Timeline

  1. 08.01.2026 12:31 1 articles · 23h ago

    NodeCordRAT Malware Discovered in Bitcoin-Themed npm Packages

    Researchers uncovered three malicious npm packages—bitcoin-main-lib, bitcoin-lib-js, and bip40—that delivered a previously undocumented remote access trojan (RAT) named NodeCordRAT. The packages were taken down in November 2025. NodeCordRAT uses Discord for command-and-control (C2) communications and is capable of stealing sensitive data from infected systems.

    Show sources

Information Snippets