Scworld
Malicious npm Packages Deploy NodeCordRAT to Target Cryptocurrency Developers
First seen 10 Jan 2026, 00:47 UTC
•
•33.6
Export
Article Content
Browse articles
In November 2025, Zscaler ThreatLabz identified three malicious npm packages designed to target cryptocurrency developers. The packages, bitcoin-main-lib and bitcoin-lib-js, install a third package, bip40, which contains the NodeCordRAT malware that steals sensitive information such as Google Chrome credentials and MetaMask seed phrases.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
Webworm APT Expands Operations to Europe with New Backdoors
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
North Korean ClickFake Campaign Targets Web3 Professionals with RATs