• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Researchers Uncover Malicious npm Packages Delivering New NodeCordRAT Malware
Share
  • bitcoinBitcoin(BTC)$78,712.00
  • ethereumEthereum(ETH)$2,320.12
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$780.45
  • rippleXRP(XRP)$1.62
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$104.56
  • tronTRON(TRX)$0.283442
  • staked-etherLido Staked Ether(STETH)$2,318.33
  • dogecoinDogecoin(DOGE)$0.108069
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Bitcoin

Researchers Uncover Malicious npm Packages Delivering New NodeCordRAT Malware

News Desk
Last updated: January 9, 2026 7:02 am
News Desk
Published: January 9, 2026
Share
npm malware

Cybersecurity experts have uncovered three malicious npm (Node Package Manager) packages linked to a new and sophisticated form of malware named NodeCordRAT. These packages, identified as “bitcoin-main-lib” and “bitcoin-lib-js,” were formulated by a user known as “wenmoonx” and were removed from the platform in November 2025.

Upon installation, these packages execute a script called postinstall.cjs, which in turn installs a package named bip40. This package acts as the vessel for the malicious payload that effectively operates as a remote access trojan (RAT), capable of stealing sensitive information from infected systems. According to researchers from Zscaler ThreatLabz, NodeCordRAT is particularly dangerous due to its capacity to extract credentials from Google Chrome, API tokens, and seed phrases from cryptocurrency wallets, including popular platforms like MetaMask.

The naming of these malicious packages mirrors legitimate repositories within the recognized bitcoinjs project, including bitcoinjs-lib and various bip packages. This tactic may serve to deceive unsuspecting developers into installing the malicious software, believing it to be legitimate.

Technical analysis reveals that both “bitcoin-main-lib” and “bitcoin-lib-js” include a package.json file containing the postinstall script that activates the NodeCordRAT payload. Once infiltrated, the malware generates a unique identifier that fingerprints the infected host, allowing it to operate across various operating systems including Windows, Linux, and macOS.

NodeCordRAT maintains communication with its command-and-control (C2) server through a hard-coded Discord server, enabling it to receive and execute remote instructions. The malware can execute commands such as:

  • !run: to run arbitrary shell commands via Node.js’ exec function,
  • !screenshot: to capture a full desktop screenshot and send the resulting PNG file to the designated Discord channel, and
  • !sendfile: to upload specific files to the same channel.

The exfiltration of stolen data utilizes Discord’s API, involving a hardcoded access token that allows the malware to transmit information to private channels. The stolen files are uploaded as message attachments through Discord’s REST endpoint, thereby creating a discreet channel for illicit activities.

The discovery of NodeCordRAT highlights ongoing risks in the cybersecurity landscape, particularly concerning open-source software repositories such as npm. Developers and organizations are urged to exercise vigilance when integrating third-party packages and to regularly audit their codebases for any suspicious activity.

Bitcoin Surges Past $115,000, Eyes Potential Rally Toward $150,000
Optimism Returns With US Institutions as Bitcoin Reclaims $91K
Is American Bitcoin a Bargain or a Value Trap? Analyzing Its True Worth
Market Experts Argue Bitcoin Still Has Significant Upside Potential Despite Recent Highs
Eventually Everyone Understands Bitcoin
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article 652d766724cd85c58695a2099131a0ff Jabil’s Stock Shows 36.5% Undervaluation Despite Recent Overvaluation Indications
Next Article LTC bearish object Medium Japanese Yen Hits Three-Week Low Against Strengthening US Dollar Amid Economic Concerns
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8509452Fbitcoin chart.jpgw1200opresize
Bitcoin’s Future Looks Promising Despite Recent Price Decline
currency jpy Medium
Japanese Yen Faces Challenges Amid US Dollar Strength and Domestic Uncertainty
f833d1066a046b5dd028f741f184ba90
Asian shares soar as tech stocks rebound and investors await earnings reports
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?