Threat actors have targeted cryptocurrency developers with three Bitcoin library-spoofing npm packages to deploy the NodeCordRAT malware, which pilfers Google Chrome-stored credentials, MetaMask seed phrases, digital keys, and API secrets, according to HackRead.Installation of the bitcoin-main-lib and bitcoin-lib-js packages enabled the automated download of the bip40 package, which contained NodeCordRAT, a report from Zscaler ThreatLabz researchers revealed. NodeCordRAT was noted to have received Discord commands to facilitate shell command execution, screenshot capturing, and file uploading."It is also possible to download bip40 as a standalone package, completely bypassing the other libraries. To deceive developers into downloading the fraudulent packages, the attacker used name variations of real repositories found within the legitimate bitcoinjs project," said researchers.While the packages, which had over 3,000 cumulative installations, have been removed from the npm repository, cryptocurrency developers have been advised to monitor their download history.
Malware, Supply chain, Threat Intelligence
Malicious npm packages spread novel NodeCordRAT malware
(Credit: Araki Illustrations – stock.adobe.com)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
