s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.nodecordrat

📛 Threat Title

Malware family: NodeCordRAT

Category: NodeCordRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.nodecordrat`. Printable name: NodeCordRAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.nodecordrat VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.nodecordrat

IOC database

Type
domain
Value
js.nodecordrat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.nodecordrat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.nodecordrat

References (1)

Remediations (10)

  • web:community.gurucul.com

    In November 2025, three malicious npm packages—bitcoin-main-lib, bitcoin-lib-js, and bip40—were identified. These packages were engineered to deploy a previously unknown remote access trojan (RAT) malware family . The malware , dubbed NodeCordRAT , propagates through npm and leverages Discord servers for command-and-control (C2) communications.

  • web:cybersecuritynews.com

    Malicious npm packages target JS devs, installing NodeCordRAT to steal browser logins, API keys, and crypto wallets.

  • web:malpedia.caad.fkie.fraunhofer.de

    NodeCordRAT is a cross-platform Remote Access Trojan and information stealer written in Node.js that targets Windows, macOS, and Linux systems through malicious NPM packages in software supply chain attacks. The malware executes automatically when developers unknowingly install compromised dependencies, providing attackers with comprehensive system access and data exfiltration capabilities ...

  • web:malware.news

    These packages were designed to deliver and install a new RAT malware family .ThreatLabz named this new malware family NodeCordRAT since it is spread via npm and uses Discord servers for C2 communication. NodeCordRAT targets Chrome credentials, sensitive secrets such as API tokens, and MetaMask (a popular cryptocurrency platform) data including ...

  • web:securitricks.com

    Description Three malicious npm packages were discovered in November 2025, designed to deliver and install a new RAT malware family named NodeCordRAT . The packages, bitcoin-main-lib, bitcoin-lib-js, and bip40, mimicked legitimate Bitcoin-related libraries to deceive developers. NodeCordRAT uses Discord for command-and-control communication, targets Chrome credentials, sensitive secrets, and ...

  • web:securityboulevard.com

    These packages were designed to deliver and install a new RAT malware family .ThreatLabz named this new malware family NodeCordRAT since it is spread via npm and uses Discord servers for C2 communication. NodeCordRAT targets Chrome credentials, sensitive secrets such as API tokens, and MetaMask (a popular cryptocurrency platform) data including ...

  • web:thehackernews.com

    Security researchers found 3 npm packages that installed NodeCordRAT malware , stealing browser data, crypto wallet secrets & tokens using Discord C2.

  • web:www.newsbreak.com

    These packages were designed to deliver and install a new RAT malware family .ThreatLabz named this new malware family NodeCordRAT since it is spread via npm and uses Discord servers for C2 communication. NodeCordRAT targets Chrome credentials, sensitive secrets such as API tokens, and MetaMask (a popular cryptocurrency platform) data including ...

  • web:www.scworld.com

    Threat actors have targeted cryptocurrency developers with three Bitcoin library-spoofing npm packages to deploy the NodeCordRAT malware , which pilfers Google Chrome-stored credentials, MetaMask seed phrases, digital keys, and API secrets, according to HackRead.

  • web:www.zscaler.com

    Key Takeaways In November 2025, three malicious npm packages, bitcoin-main-lib, bitcoin-lib-js, and bip40, were discovered. These packages were designed to deliver and install a new RAT malware family . ThreatLabz named this new malware family NodeCordRAT since it is spread via npm and uses Discord servers for C2 communication. NodeCordRAT targets Chrome credentials, sensitive secrets such as ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.