• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Researchers Uncover Malicious npm Packages Delivering New NodeCordRAT Malware
Share
  • bitcoinBitcoin(BTC)$95,701.00
  • ethereumEthereum(ETH)$3,324.52
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$933.33
  • rippleXRP(XRP)$2.09
  • solanaSolana(SOL)$142.52
  • usd-coinUSDC(USDC)$1.00
  • staked-etherLido Staked Ether(STETH)$3,326.29
  • tronTRON(TRX)$0.307930
  • dogecoinDogecoin(DOGE)$0.141807
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Bitcoin

Researchers Uncover Malicious npm Packages Delivering New NodeCordRAT Malware

News Desk
Last updated: January 9, 2026 7:02 am
News Desk
Published: January 9, 2026
Share
npm malware

Cybersecurity experts have uncovered three malicious npm (Node Package Manager) packages linked to a new and sophisticated form of malware named NodeCordRAT. These packages, identified as “bitcoin-main-lib” and “bitcoin-lib-js,” were formulated by a user known as “wenmoonx” and were removed from the platform in November 2025.

Upon installation, these packages execute a script called postinstall.cjs, which in turn installs a package named bip40. This package acts as the vessel for the malicious payload that effectively operates as a remote access trojan (RAT), capable of stealing sensitive information from infected systems. According to researchers from Zscaler ThreatLabz, NodeCordRAT is particularly dangerous due to its capacity to extract credentials from Google Chrome, API tokens, and seed phrases from cryptocurrency wallets, including popular platforms like MetaMask.

The naming of these malicious packages mirrors legitimate repositories within the recognized bitcoinjs project, including bitcoinjs-lib and various bip packages. This tactic may serve to deceive unsuspecting developers into installing the malicious software, believing it to be legitimate.

Technical analysis reveals that both “bitcoin-main-lib” and “bitcoin-lib-js” include a package.json file containing the postinstall script that activates the NodeCordRAT payload. Once infiltrated, the malware generates a unique identifier that fingerprints the infected host, allowing it to operate across various operating systems including Windows, Linux, and macOS.

NodeCordRAT maintains communication with its command-and-control (C2) server through a hard-coded Discord server, enabling it to receive and execute remote instructions. The malware can execute commands such as:

  • !run: to run arbitrary shell commands via Node.js’ exec function,
  • !screenshot: to capture a full desktop screenshot and send the resulting PNG file to the designated Discord channel, and
  • !sendfile: to upload specific files to the same channel.

The exfiltration of stolen data utilizes Discord’s API, involving a hardcoded access token that allows the malware to transmit information to private channels. The stolen files are uploaded as message attachments through Discord’s REST endpoint, thereby creating a discreet channel for illicit activities.

The discovery of NodeCordRAT highlights ongoing risks in the cybersecurity landscape, particularly concerning open-source software repositories such as npm. Developers and organizations are urged to exercise vigilance when integrating third-party packages and to regularly audit their codebases for any suspicious activity.

Time to Buy the Dip on Bitcoin as Price Dips Below $100,000
Bitcoin Proponents Celebrate Launch of PubKey D.C. with High-Profile Guests
Priority Power CEO Addresses Misconceptions Ahead of College Station City Council Vote on Data Facility
Digital gold vs. gold: Which is the better investment?
Bitcoin Price Target Increased Amid Quantum Threat Mitigation Discussion
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article 652d766724cd85c58695a2099131a0ff Jabil’s Stock Shows 36.5% Undervaluation Despite Recent Overvaluation Indications
Next Article LTC bearish object Medium Japanese Yen Hits Three-Week Low Against Strengthening US Dollar Amid Economic Concerns
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
Woman on bed with credit card and laptop
Understanding Credit Card Offers and Financial Compensation
XRP Crashes As Ripples Luxembourg EMI Push Fails To Lift Price.webp
XRP Experiences Market Decline Despite Ripple’s Regulatory Advances in Europe
podium7 12.webp
Ethereum Staking Hits 1.5 Million ETH as Institutions Bet on Stability While Investors Eye DeepSnitch AI for Asymmetric Gains
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • News
  • Finance
  • Company
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?