TF-MAL-js.nodecordrat
📛 Threat Title
Malware family: NodeCordRAT
Description
ThreatFox malware family `js.nodecordrat`. Printable name: NodeCordRAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.nodecordrat
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.nodecordrat
IOC database
- Type
- domain
- Value
js.nodecordrat- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.nodecordrat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.nodecordrat
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:community.gurucul.com
In November 2025, three malicious npm packages—bitcoin-main-lib, bitcoin-lib-js, and bip40—were identified. These packages were engineered to deploy a previously unknown remote access trojan (RAT) malware family . The malware , dubbed NodeCordRAT , propagates through npm and leverages Discord servers for command-and-control (C2) communications.
-
web:cybersecuritynews.com
Malicious npm packages target JS devs, installing NodeCordRAT to steal browser logins, API keys, and crypto wallets.
-
web:malpedia.caad.fkie.fraunhofer.de
NodeCordRAT is a cross-platform Remote Access Trojan and information stealer written in Node.js that targets Windows, macOS, and Linux systems through malicious NPM packages in software supply chain attacks. The malware executes automatically when developers unknowingly install compromised dependencies, providing attackers with comprehensive system access and data exfiltration capabilities ...
-
web:malware.news
These packages were designed to deliver and install a new RAT malware family .ThreatLabz named this new malware family NodeCordRAT since it is spread via npm and uses Discord servers for C2 communication. NodeCordRAT targets Chrome credentials, sensitive secrets such as API tokens, and MetaMask (a popular cryptocurrency platform) data including ...
-
web:securitricks.com
Description Three malicious npm packages were discovered in November 2025, designed to deliver and install a new RAT malware family named NodeCordRAT . The packages, bitcoin-main-lib, bitcoin-lib-js, and bip40, mimicked legitimate Bitcoin-related libraries to deceive developers. NodeCordRAT uses Discord for command-and-control communication, targets Chrome credentials, sensitive secrets, and ...
-
web:securityboulevard.com
These packages were designed to deliver and install a new RAT malware family .ThreatLabz named this new malware family NodeCordRAT since it is spread via npm and uses Discord servers for C2 communication. NodeCordRAT targets Chrome credentials, sensitive secrets such as API tokens, and MetaMask (a popular cryptocurrency platform) data including ...
-
web:thehackernews.com
Security researchers found 3 npm packages that installed NodeCordRAT malware , stealing browser data, crypto wallet secrets & tokens using Discord C2.
-
web:www.newsbreak.com
These packages were designed to deliver and install a new RAT malware family .ThreatLabz named this new malware family NodeCordRAT since it is spread via npm and uses Discord servers for C2 communication. NodeCordRAT targets Chrome credentials, sensitive secrets such as API tokens, and MetaMask (a popular cryptocurrency platform) data including ...
-
web:www.scworld.com
Threat actors have targeted cryptocurrency developers with three Bitcoin library-spoofing npm packages to deploy the NodeCordRAT malware , which pilfers Google Chrome-stored credentials, MetaMask seed phrases, digital keys, and API secrets, according to HackRead.
-
web:www.zscaler.com
Key Takeaways In November 2025, three malicious npm packages, bitcoin-main-lib, bitcoin-lib-js, and bip40, were discovered. These packages were designed to deliver and install a new RAT malware family . ThreatLabz named this new malware family NodeCordRAT since it is spread via npm and uses Discord servers for C2 communication. NodeCordRAT targets Chrome credentials, sensitive secrets such as ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.