Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

NodeCordRAT

NodeCordRAT is a previously undocumented Node.js-based remote access trojan (RAT) with data-stealing capabilities, discovered by Zscaler ThreatLabz and distributed through malicious npm packages. The campaign used three packages—bitcoin-main-lib, bitcoin-lib-js, and bip40—named to mimic legitimate bitcoinjs-related libraries and target developers, particularly those working with cryptocurrency tooling. The packages were discovered and removed in November 2025 after being downloaded several thousand times; reporting also attributes the uploads to the npm user "wenmoonx." The infection chain used postinstall scripts in bitcoin-main-lib and bitcoin-lib-js to install bip40, which contained the NodeCordRAT payload, and the installation occurred without user prompts or warnings. NodeCordRAT uses Discord servers and Discord's API for command-and-control, including exfiltration to a private Discord channel via a hardcoded bot token, helping its traffic blend with legitimate Discord activity. Reported capabilities include remote shell command execution, file upload/exfiltration, screenshot capture, host fingerprinting across Windows, Linux, and macOS, and theft of Google Chrome credentials, Chrome profile login data and Local State, API tokens/secrets, recursively discovered .env files, and cryptocurrency wallet seed phrases, including MetaMask data associated with extension ID nkbihfbeogaeaoehlefnkodbefgpgknn. The campaign is a software supply-chain attack through the npm ecosystem and is directly associated in the content with malicious packages bitcoin-main-lib, bitcoin-lib-js, and bip40.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1195Supply Chain CompromiseEvidence1

"Notepad++ Official Update Mechanism Hijacked to Deliver Malware..."; "eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware"; "Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems"; "Open VSX Supply Chain Attack..."; "Malicious Chrome Extensions..."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.