typeanalysisfamilynovashadowconfidencemediumcreated2026-08-21updated2026-08-21scriptmalware-familyratinfostealerc2persistencedefense-evasiondiscoveryc2-protocolexfiltrationmitre-attck
SHA-256: 7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520

novashadow: 7ab76063 — French-language JavaScript RAT with Socket.IO C2, Discord injection, and browser credential theft

Executive Summary: A ~592 KB Node.js JavaScript RAT branded "Nova Shadow" by its author. Bundled with Parcel and obfuscated via javascript-obfuscator, it uses Socket.IO for real-time C2, steals Chromium/Opera GX/Firefox credentials via DPAPI and AES-GCM, injects Discord's desktop_core, exfiltrates via GoFile.io, and notifies operators via Discord webhook and Telegram Bot API. French-language strings, room-code sessioning, and a web panel at 144.172.93.158 distinguish this family.


What It Is

  • File: atribuyeres_deobfuscated.js — 592 207 bytes, UTF-8 JavaScript source with very long lines ^[file.txt]
  • Type: Node.js script (not PE/ELF), requiring a JavaScript runtime ^[triage.json]
  • Obfuscation: javascript-obfuscator (control-flow flattening, string-array lookup, dead-code injection, __p_ prefix variable mangling) ^[strings.txt:1]
  • Bundler: Parcel (parcelRequire runtime and module map) ^[strings.txt:1347]
  • Family: novashadow (preliminary OpenCTI label, first confirmed corpus sample) ^[triage.json]
  • Confidence: Medium — single sample, but branding and infrastructure are distinctive

How It Works

Entry Point and Architecture

The script is a Parcel-bundled single file exposing a parcelRequire module loader. At line 1347 it maps internal modules: system/antidebug, system/core, system/uac, system/start, network/downloadzip, network/pong, serveur/revershell, serveur/commande, serveur/fileHandlers, serveur/screenshare, serveur/alertHandlers, security/injection, games/gameManager, panel/panelHandlers, debug/debugManager ^[strings.txt:1347]. The entry module loads configuration, initializes the Socket.IO client, and wires event handlers.

C2 and Sessioning

  • Primary C2: socket.io-client connecting to http://144.172.93.158 with query.attackerId = '688247e822ac7d8792c4971f' ^[strings.txt:5300]
  • Room code: Generated on startup for victim session isolation; shared via Discord webhook and Telegram Bot API ^[strings.txt:5300]
  • Panel: Web UI at http://144.172.93.158/view for attacker access ^[strings.txt:1486]
  • Events: client-execute-command (remote shell), start-screen-sharing, stop-screen-sharing, file-chunk, file-complete, request-files, ping-room / pong-room ^[strings.txt:813-965]

Credential Theft

  • Chromium family: Targets 32+ browsers including Chrome, Edge, Brave, Vivaldi, Opera, Yandex, and 360Browser ^[strings.txt:3785]. Reads Local State for the DPAPI-encrypted os_crypt.encrypted_key, slices the Base64 payload, and decrypts via AES-256-GCM using Node.js crypto.createDecipheriv ^[strings.txt:3370-3387]. Extracts Login Data (passwords), Web Data (autofills), and Network/Cookies ^[strings.txt:4203-4239].
  • Opera GX: Dedicated bypass module using --remote-debugging-port CDP injection to dump cookies via Network.getAllCookies ^[strings.txt:984-1025]. Also extracts passwords and autofills from Opera GX profile directories ^[strings.txt:4203-4250].
  • Firefox: Reads %APPDATA%/Mozilla/Firefox/Profiles/*/cookies.sqlite and logins.json via node-sqlite3 ^[strings.txt:4428-4456].

Discord Abuse

  • Token theft: Enumerates %APPDATA%/Discord*/Local Storage/leveldb/*.ldb and %APPDATA%/Discord*/*.localstorage for tokens, then queries Discord API v9/v10 for user profile, billing, relationships, and Nitro status ^[strings.txt:3404-3499].
  • Desktop core injection: Downloads a template from DSCINJ_URL (https://raw.githubusercontent.com/KSCHcuck1/sub/refs/heads/main/index.js by default), patches %TRANSFER_URL% and %DISABLE_2FA% placeholders, writes to discord_desktop_core/index.js, creates a ThiefCat subdirectory, and relaunches Discord ^[strings.txt:3548-3566].

Exfiltration

  • GoFile.io: Stolen data is zipped (via adm-zip) and uploaded via axios + form-data to https://<server>.gofile.io/uploadFile. The server name is selected from a hardcoded server list ^[strings.txt:4652].
  • Discord webhook: Hardcoded webhook https://discord.com/api/webhooks/1397933340589555864/l6oE_E3dR1zzX-nLxUZNPZkMustt9BqG-t7eVvWUJ0r6OVKyLxPnSsBCZDHWbBYIexTX posts room code, attacker ID, device name, and panel link ^[strings.txt:5300].
  • Telegram Bot API: Optional notification via api.telegram.org/bot<token>/sendMessage with Markdown-formatted room code and panel link ^[strings.txt:1524-1526].

Anti-Analysis and Evasion

  • Remote blacklist: On startup, fetches JSON blacklists from raw.githubusercontent.com/Mynva/sub/main/json/ for programs (nope.json), GPU types, OS names, PC names, running processes, HWIDs, and IPs. Matching processes are killed via WMI ^[strings.txt:1612-1678].
  • Anti-debug: References ./system/antidebug.js — exact checks not recovered in this deobfuscated view ^[strings.txt:1347].
  • Fake error: Optional Application Error message box (Config_FakeError = 'no' in this build) ^[strings.txt:5300].

Persistence and Privilege Escalation

  • UAC bypass: Generates a VBScript that uses WScript.Shell + ShellApplication.ShellExecute with runas verb and window hidden (0) to relaunch the Node.js executable with elevated privileges. Success/cancel flags are signaled via temp files (uac_success_*, uac_canceled_*) ^[strings.txt:2095-2130].
  • Registry Run: reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v <basename> /t REG_SZ /d "<execPath>" /f ^[strings.txt:5915].
  • Startup check: Queries whether the binary is already in the startup path via WMI process enumeration ^[strings.txt:1971].

Remote Shell

Spawns PowerShell (powershell -Command) and Node.js child_process.exec for remote command execution. Output is streamed back to the Socket.IO room via command-output and client-execute events ^[strings.txt:831-920]. Also implements a reverse-shell module (serveur/revershell.js) ^[strings.txt:1347].


Source-Code Behaviour

The deobfuscated source reveals a modular architecture typical of Parcel-bundled Node.js applications. Key behavioural chains:

  1. Config load → attackerId, webhook, telegram tokens, DSCINJ_URL, feature flags
  2. Anti-analysis gate → fetch remote blacklists → kill matching processes
  3. UAC elevation → VBScript ShellExecute → wait for temp-file signal
  4. Socket.IO connect → join room → emit join-message with system fingerprint
  5. Credential harvest → Chromium DPAPI/AES-GCM → Opera GX CDP → Firefox SQLite → zip → GoFile upload
  6. Discord token extract → API queries → discordTokenData event
  7. Discord injection → fetch template → patch → write desktop_core/index.js → relaunch Discord
  8. Notifications → webhook embed + Telegram message with room code and panel link
  9. Event loop → client-execute-command, start-screen-sharing, request-files

C2 Infrastructure

Type Value Note
Socket.IO C2 http://144.172.93.158 Hardcoded; no TLS in default config
Panel http://144.172.93.158/view Web-based operator panel
Hub http://144.172.93.158/hub.html?roomId=<code> Victim access link
Discord webhook 1397933340589555864/... Hardcoded; room-code notification
Telegram placeholders (%TELEGRAM_BOT_TOKEN%) Optional; not configured in this build
GitHub config raw.githubusercontent.com/Mynva/sub/main/json/ Blacklist JSON files
Discord inj template raw.githubusercontent.com/KSCHcuck1/sub/refs/heads/main/index.js Default DSCINJ_URL
Screenshot ZIP github.com/KSCHcuck1/cooc/raw/refs/heads/main/screenshot-desktop.zip Downloaded at runtime for screen-share support
Brand asset raw.githubusercontent.com/KSCHcuck/sub/main/assets/shadow-_1_.png Logo for Discord embed
Telegram contact @Nova Shadow | https://t.me/Sordeal Developer branding

Interesting Tidbits

  • French provenance: Extensive French strings (Envoi au serveur, Commande reçue, Fermeture de la session PowerShell, L'utilisateur a refusé, Vol de <n> token(s) Discord terminé) indicate a French-speaking author or target audience ^[strings.txt:837-1528].
  • Shadow branding: The malware names itself "Nova Shadow", uses a GitHub org KSCHcuck/KSCHcuck1/Mynva, and a Telegram channel t.me/Sordeal. The branding is consistent across C2 panel, Discord embed, and Telegram messages ^[strings.txt:1486-1524].
  • Room-code model: Each victim gets a unique room code (similar to TeamViewer or AnyDesk session IDs), enabling multi-victim management from a single Socket.IO server ^[strings.txt:5300].
  • Dual exfil stack: GoFile.io for bulk file uploads, Discord webhook for lightweight notifications, with Telegram as a fallback — a redundant exfil architecture.
  • CDP hijacking for Opera GX: Rather than reading Opera's SQLite directly, the malware injects a Chrome extension manifest and launches Opera with --remote-debugging-port to harvest cookies via CDP Network.getAllCookies ^[strings.txt:984-1025].
  • Process blacklisting: The remote blacklist includes not just AV names but GPU types, OS versions, PC hostnames, and HWIDs — suggesting the author uses this to filter sandbox VMs and researcher machines ^[strings.txt:1628-1678].
  • Hardcoded attacker ID: 688247e822ac7d8792c4971f is a 24-character hex string, likely a MongoDB-style ObjectId or a generated UUID, used to identify the operator in multi-tenant panel deployments.

How To Mess With It (Homelab Replication)

Goal: Reproduce a comparable JavaScript RAT fingerprint.

  1. Toolchain: Node.js 20+, Parcel bundler, javascript-obfuscator CLI
  2. Core deps: socket.io-client, axios, adm-zip, form-data, node-sqlite3, ws
  3. Build:
    npm init -y
    npm install socket.io-client axios adm-zip form-data ws
    npx parcel build src/index.js --target node --bundle-node-modules
    npx javascript-obfuscator dist/index.js --output nova.js \
      --control-flow-flattening true \
      --string-array true \
      --dead-code-injection true
    
  4. Verify: The resulting nova.js should contain parcelRequire, __p_ mangled names, and socket.io-client strings. A quick grep -c 'socket.io-client' nova.js should return >0.
  5. What you'll learn: How Parcel collapses Node.js module graphs into a single opaque file, and how javascript-obfuscator poisons static analysis while preserving runtime behaviour.

Deployable Signatures

YARA Rule

rule Novashadow_JS_RAT {
    meta:
        description = "Nova Shadow JavaScript RAT / stealer"
        author = "PacketPursuit"
        date = "2026-08-21"
        hash = "7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520"
    strings:
        $a1 = "socket.io-client" ascii wide
        $a2 = "parcelRequire" ascii wide
        $a3 = "Nova Shadow" ascii wide
        $a4 = "144.172.93.158" ascii wide
        $a5 = "discord_desktop_core" ascii wide
        $a6 = "ThiefCat" ascii wide
        $a7 = "gofile.io/uploadFile" ascii wide
        $a8 = "Network.getAllCookies" ascii wide
        $b1 = /__p_\d{6,10}/ ascii
        $b2 = "javascript-obfuscator" ascii wide
    condition:
        filesize < 1MB and
        uint16be(0) != 0x4d5a and // not PE
        (4 of ($a*) or (3 of ($a*) and $b1))
}

Behavioral Hunt Query (Sigma-like)

title: Nova Shadow JS RAT Behaviour
detection:
  selection_process:
    - Image|endswith:
        - '\node.exe'
        - '\node'
    - CommandLine|contains:
        - '144.172.93.158'
        - 'socket.io-client'
  selection_file:
    TargetFilename|contains:
      - 'discord_desktop_core\index.js'
      - 'ThiefCat'
    TargetFilename|endswith:
      - '_cookies.txt'
      - 'passwords.txt'
      - 'autofills.txt'
  selection_registry:
    EventType: SetValue
    TargetObject|contains: 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
    Details|contains: '.js'
  selection_network:
    Initiated: true
    DestinationHostname|contains:
      - 'gofile.io'
      - '144.172.93.158'
  condition: selection_process or selection_file or selection_registry or selection_network

IOC List

Type Indicator
SHA-256 7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520
C2 IP 144.172.93.158
Discord webhook ID 1397933340589555864
GitHub config org Mynva
GitHub asset org KSCHcuck, KSCHcuck1
Telegram channel t.me/Sordeal
Brand Nova Shadow
Panel URL http://144.172.93.158/view
Attacker ID 688247e822ac7d8792c4971f
File paths %TEMP%\ele_*.vbs, %TEMP%\uac_success_*.tmp, %TEMP%\uac_canceled_*.tmp, %TEMP%\BrowserData.zip
Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Behavioural Fingerprint

This JavaScript sample, when executed under Node.js, immediately fetches remote JSON blacklists from GitHub Raw, kills matching processes via WMI, generates a VBScript in %TEMP% to elevate via ShellApplication.ShellExecute, connects to a Socket.IO server at 144.172.93.158, and emits a join-message with a room code and system fingerprint. Within 60 seconds it enumerates 32+ Chromium-based browser profiles, decrypts Local State via DPAPI and AES-256-GCM, dumps Login Data passwords and Network/Cookies, exfiltrates a ZIP to GoFile.io, and notifies the operator via Discord webhook embed. If Opera GX is present, it launches the browser with --remote-debugging-port and extracts cookies via Chrome DevTools Protocol Network.getAllCookies. It also patches Discord's desktop_core/index.js after downloading an injection template from GitHub.


Detection Signatures

ATT&CK ID Name Source
T1059.003 Windows Command Shell Remote shell via child_process.exec and PowerShell spawn ^[strings.txt:831]
T1059.001 PowerShell System enumeration commands (Get-CimInstance, Get-NetAdapter) ^[strings.txt:601-707]
T1071.001 Application Layer Protocol: Web Protocols Socket.IO over HTTP C2 ^[strings.txt:5300]
T1567.002 Exfiltration to Cloud Storage GoFile.io upload ^[strings.txt:4652]
T1056.001 Input Capture: Keylogging Screen sharing module ^[strings.txt:958]
T1518.001 Software Discovery Browser and process enumeration ^[strings.txt:3785]
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys reg add HKCU\...\Run ^[strings.txt:5915]
T1548.002 Abuse Elevation Control Mechanism: Bypass UAC VBScript ShellApplication.ShellExecute with runas ^[strings.txt:2095]
T1555.003 Credentials from Web Browsers Chromium DPAPI + AES-256-GCM decryption ^[strings.txt:3370-3387]
T1555 Credentials from Password Stores Opera GX, Firefox SQLite credential extraction ^[strings.txt:4203-4456]
T1083 File and Directory Discovery File manager handlers via Socket.IO events ^[strings.txt:2755]
T1113 Screen Capture Screen-sharing module with screenshot-desktop.zip download ^[strings.txt:2378]
T1497.001 Virtualization/Sandbox Evasion Remote blacklist process killing ^[strings.txt:1612-1621]
T1070.004 File Deletion Self-deletion of VBScript after UAC attempt ^[strings.txt:2120]

References


Provenance

Analysis based on static inspection of the deobfuscated JavaScript source. Tools: file (magic), exiftool (metadata), strings (surface strings), grep (targeted extraction), custom javascript-deobfuscator inference. No dynamic execution performed — CAPE skipped this sample because it is not a supported binary class ^[dynamic-analysis.md]. Tool versions not recorded for this triage pass.