Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Researchers discover NodeCordRAT hidden in npm Bitcoin-themed packages
Celebrities

Researchers discover NodeCordRAT hidden in npm Bitcoin-themed packages

By January 8, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 8, 2026Rabi LakshmananMalware/Cloud Security

NodeCordRAT hidden in npm

Cybersecurity researchers discovered three malicious npm packages designed to deliver previously undocumented malware called NodeCordRAT.

Below are the names of all removed packages as of November 2025. These were uploaded by a user named ‘wenmoonx’.

“The bitcoin-main-lib and bitcoin-lib-js packages run a postinstall.cjs script during installation, which installs bip40, a package containing a malicious payload,” said Satyam Singh and Lakhan Parashar, researchers at Zscaler ThreatLabz. “This final payload, named NodeCordRAT by ThreatLabz, is a remote access Trojan (RAT) with data-stealing capabilities.”

NodeCordRAT’s name comes from its use of npm as a propagation vector and Discord server for command and control (C2) communication. This malware has the ability to steal Google Chrome credentials, API tokens, and seed phrases from cryptocurrency wallets such as MetaMask.

cyber security

According to the cybersecurity firm, the attackers behind the campaign are credited with naming their packages after actual repositories found within the legitimate bitcoinjs project, such as bitcoinjs-lib, bip32, bip38, and bip38.

Both “bitcoin-main-lib” and “bitcoin-lib-js” include a “package.json” file with “postinstall.cjs” as a post-installation script, leading to the execution of “bip40” containing the NodeCordRAT payload.

The malware fingerprints infected hosts to generate a unique identifier across Windows, Linux, and macOS systems, and utilizes a hardcoded Discord server to open a secret communication channel to receive and execute instructions.

!run, execute any shell command using Node.js’s exec function. !screenshot, takes a complete screenshot of your desktop and extracts the PNG file to your Discord channel. !sendfile, uploads the specified file to a Discord channel.

“This data is extracted using Discord’s API, which includes hard-coded tokens, and sent to a private channel,” Zscaler said. “Stolen files are uploaded as message attachments via Discord’s REST endpoint /channels/{id}/messages.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleVera C. Rubin Observatory discovers record-breaking giant asteroid in first seven days of observations
Next Article Rings around M dwarf provide new clues about planetary habitability

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

Trending Posts

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

June 16, 2026

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.