Malicious npm Packages Deploy NodeCordRAT to Target Cryptocurrency Developers

Malicious npm Packages Deploy NodeCordRAT to Target Cryptocurrency Developers

First seen 10 Jan 2026, 00:47 UTC ZscalerScworld 33.6

Article Content

Browse articles
ThreatCluster

In November 2025, Zscaler ThreatLabz identified three malicious npm packages designed to target cryptocurrency developers. The packages, bitcoin-main-lib and bitcoin-lib-js, install a third package, bip40, which contains the NodeCordRAT malware that steals sensitive information such as Google Chrome credentials and MetaMask seed phrases.