The security research organization Zscaler ThreatLabz discovered three malicious npm packages disguised as Bitcoin-related libraries (bitcoin-main-lib, bitcoin-lib-js, bip40). Before being taken down, they were downloaded over 3,400 times and used to implant a remote control Trojan called NodeCordRAT. NodeCordRAT can steal Chrome login credentials, API tokens, and MetaMask wallet private keys/mnemonics, and it can be controlled via commands through a Discord server. The malware is activated through installation scripts without the developer's knowledge. Security teams warn that npm supply chain risks are still rising. (cryptopolitan)

BTC0,5%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • بالعربية
  • Português (Brasil)
  • 简体中文
  • English
  • Español
  • Français (Afrique)
  • Bahasa Indonesia
  • 日本語
  • Português (Portugal)
  • Русский
  • 繁體中文
  • Українська
  • Tiếng Việt