Emergence of Tsundere Botnet Exploiting Node.js and Cryptocurrency Packages
First seen 23 Nov 2025, 03:35 UTC
•
•0% similarity
•29
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Tsundere botnet, identified by Kaspersky GReAT in mid-2025, targets Windows, Linux, and macOS users by leveraging legitimate Node.js packages and blockchain technology. Initially observed in October 2024, it utilizes a malicious MSI installer and exploits the Ethereum blockchain for command-and-control operations.
ThreatCluster AI
How this analysis works