The security research organization Zscaler ThreatLabz discovered three malicious npm packages disguised as Bitcoin-related libraries (bitcoin-main-lib, bitcoin-lib-js, bip40). Before being taken down, they were downloaded over 3,400 times and used to implant a remote control Trojan called NodeCordRAT. NodeCordRAT can steal Chrome login credentials, API tokens, and MetaMask wallet private keys/mnemonics, and it can be controlled via commands through a Discord server. The malware is activated through installation scripts without the developer's knowledge. Security teams warn that npm supply chain risks are still rising. (cryptopolitan)
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
The security research organization Zscaler ThreatLabz discovered three malicious npm packages disguised as Bitcoin-related libraries (bitcoin-main-lib, bitcoin-lib-js, bip40). Before being taken down, they were downloaded over 3,400 times and used to implant a remote control Trojan called NodeCordRAT. NodeCordRAT can steal Chrome login credentials, API tokens, and MetaMask wallet private keys/mnemonics, and it can be controlled via commands through a Discord server. The malware is activated through installation scripts without the developer's knowledge. Security teams warn that npm supply chain risks are still rising. (cryptopolitan)