Malware, Supply chain, Threat Intelligence

Malicious npm packages spread novel NodeCordRAT malware

(Credit: Araki Illustrations – stock.adobe.com)

Threat actors have targeted cryptocurrency developers with three Bitcoin library-spoofing npm packages to deploy the NodeCordRAT malware, which pilfers Google Chrome-stored credentials, MetaMask seed phrases, digital keys, and API secrets, according to HackRead.

Installation of the bitcoin-main-lib and bitcoin-lib-js packages enabled the automated download of the bip40 package, which contained NodeCordRAT, a report from Zscaler ThreatLabz researchers revealed. NodeCordRAT was noted to have received Discord commands to facilitate shell command execution, screenshot capturing, and file uploading.

"It is also possible to download bip40 as a standalone package, completely bypassing the other libraries. To deceive developers into downloading the fraudulent packages, the attacker used name variations of real repositories found within the legitimate bitcoinjs project," said researchers.

While the packages, which had over 3,000 cumulative installations, have been removed from the npm repository, cryptocurrency developers have been advised to monitor their download history.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds