Three malicious npm packages—bitcoin-main-lib, bitcoin-lib-js, and bip40—were discovered on the public npm registry, targeting JavaScript developers by masquerading as legitimate bitcoinjs project components. These packages, uploaded by a user named "wenmoonx," delivered a previously undocumented remote access trojan (RAT) dubbed NodeCordRAT. The infection chain began when developers installed either bitcoin-main-lib or bitcoin-lib-js, which executed a post-install script to fetch and install bip40, the package containing the actual malware payload. Once active, NodeCordRAT enabled attackers to steal browser credentials, API keys, and cryptocurrency wallet data, particularly targeting Chrome login databases, .env files, and MetaMask wallet information.
NodeCordRAT is written in Node.js and uses Discord as its command-and-control (C2) channel, allowing attackers to remotely execute shell commands, take screenshots, and exfiltrate files from compromised developer systems. The malware is cross-platform, capable of fingerprinting infected hosts on Windows, Linux, and macOS, and uses Discord's API for covert data exfiltration. The campaign was identified by Zscaler ThreatLabz in November 2025, and all three malicious packages have since been removed from the npm registry. The attack highlights the ongoing risk of supply chain threats in open-source ecosystems, especially for developers handling sensitive credentials and production access.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Multiple security outlets reported Zscaler ThreatLabz's findings, publicly detailing the malicious packages, their Discord-based control mechanism, and the risks posed to developers and organizations using open-source dependencies.
By November 2025, the three identified packages had been taken down from the npm registry following their discovery. Reports noted that the packages may already have been downloaded thousands of times before removal.
In November 2025, Zscaler ThreatLabz identified the three malicious npm packages as delivering a new cross-platform remote access trojan called NodeCordRAT via postinstall scripts. The malware enabled command execution, screenshot capture, file theft, and exfiltration of Chrome credentials, API tokens, and cryptocurrency wallet seed phrases through a hard-coded Discord-based command-and-control channel.
Threat actors uploaded three npm packages—bitcoin-main-lib, bitcoin-lib-js, and bip40—under the user name "wenmoonx" to impersonate legitimate bitcoinjs-related projects and target developers, particularly in the cryptocurrency sector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.