7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520novashadow: 7ab76063 — French-language JavaScript RAT with Socket.IO C2, Discord injection, and browser credential theft
Executive Summary: A ~592 KB Node.js JavaScript RAT branded "Nova Shadow" by its author. Bundled with Parcel and obfuscated via javascript-obfuscator, it uses Socket.IO for real-time C2, steals Chromium/Opera GX/Firefox credentials via DPAPI and AES-GCM, injects Discord's desktop_core, exfiltrates via GoFile.io, and notifies operators via Discord webhook and Telegram Bot API. French-language strings, room-code sessioning, and a web panel at 144.172.93.158 distinguish this family.
What It Is
- File:
atribuyeres_deobfuscated.js— 592 207 bytes, UTF-8 JavaScript source with very long lines ^[file.txt] - Type: Node.js script (not PE/ELF), requiring a JavaScript runtime ^[triage.json]
- Obfuscation:
javascript-obfuscator(control-flow flattening, string-array lookup, dead-code injection,__p_prefix variable mangling) ^[strings.txt:1] - Bundler: Parcel (
parcelRequireruntime and module map) ^[strings.txt:1347] - Family:
novashadow(preliminary OpenCTI label, first confirmed corpus sample) ^[triage.json] - Confidence: Medium — single sample, but branding and infrastructure are distinctive
How It Works
Entry Point and Architecture
The script is a Parcel-bundled single file exposing a parcelRequire module loader. At line 1347 it maps internal modules: system/antidebug, system/core, system/uac, system/start, network/downloadzip, network/pong, serveur/revershell, serveur/commande, serveur/fileHandlers, serveur/screenshare, serveur/alertHandlers, security/injection, games/gameManager, panel/panelHandlers, debug/debugManager ^[strings.txt:1347]. The entry module loads configuration, initializes the Socket.IO client, and wires event handlers.
C2 and Sessioning
- Primary C2:
socket.io-clientconnecting tohttp://144.172.93.158withquery.attackerId = '688247e822ac7d8792c4971f'^[strings.txt:5300] - Room code: Generated on startup for victim session isolation; shared via Discord webhook and Telegram Bot API ^[strings.txt:5300]
- Panel: Web UI at
http://144.172.93.158/viewfor attacker access ^[strings.txt:1486] - Events:
client-execute-command(remote shell),start-screen-sharing,stop-screen-sharing,file-chunk,file-complete,request-files,ping-room/pong-room^[strings.txt:813-965]
Credential Theft
- Chromium family: Targets 32+ browsers including Chrome, Edge, Brave, Vivaldi, Opera, Yandex, and 360Browser ^[strings.txt:3785]. Reads
Local Statefor the DPAPI-encryptedos_crypt.encrypted_key, slices the Base64 payload, and decrypts via AES-256-GCM using Node.jscrypto.createDecipheriv^[strings.txt:3370-3387]. ExtractsLogin Data(passwords),Web Data(autofills), andNetwork/Cookies^[strings.txt:4203-4239]. - Opera GX: Dedicated bypass module using
--remote-debugging-portCDP injection to dump cookies viaNetwork.getAllCookies^[strings.txt:984-1025]. Also extracts passwords and autofills from Opera GX profile directories ^[strings.txt:4203-4250]. - Firefox: Reads
%APPDATA%/Mozilla/Firefox/Profiles/*/cookies.sqliteandlogins.jsonvianode-sqlite3^[strings.txt:4428-4456].
Discord Abuse
- Token theft: Enumerates
%APPDATA%/Discord*/Local Storage/leveldb/*.ldband%APPDATA%/Discord*/*.localstoragefor tokens, then queries Discord API v9/v10 for user profile, billing, relationships, and Nitro status ^[strings.txt:3404-3499]. - Desktop core injection: Downloads a template from
DSCINJ_URL(https://raw.githubusercontent.com/KSCHcuck1/sub/refs/heads/main/index.jsby default), patches%TRANSFER_URL%and%DISABLE_2FA%placeholders, writes todiscord_desktop_core/index.js, creates aThiefCatsubdirectory, and relaunches Discord ^[strings.txt:3548-3566].
Exfiltration
- GoFile.io: Stolen data is zipped (via
adm-zip) and uploaded viaaxios+form-datatohttps://<server>.gofile.io/uploadFile. The server name is selected from a hardcoded server list ^[strings.txt:4652]. - Discord webhook: Hardcoded webhook
https://discord.com/api/webhooks/1397933340589555864/l6oE_E3dR1zzX-nLxUZNPZkMustt9BqG-t7eVvWUJ0r6OVKyLxPnSsBCZDHWbBYIexTXposts room code, attacker ID, device name, and panel link ^[strings.txt:5300]. - Telegram Bot API: Optional notification via
api.telegram.org/bot<token>/sendMessagewith Markdown-formatted room code and panel link ^[strings.txt:1524-1526].
Anti-Analysis and Evasion
- Remote blacklist: On startup, fetches JSON blacklists from
raw.githubusercontent.com/Mynva/sub/main/json/for programs (nope.json), GPU types, OS names, PC names, running processes, HWIDs, and IPs. Matching processes are killed via WMI ^[strings.txt:1612-1678]. - Anti-debug: References
./system/antidebug.js— exact checks not recovered in this deobfuscated view ^[strings.txt:1347]. - Fake error: Optional
Application Errormessage box (Config_FakeError = 'no'in this build) ^[strings.txt:5300].
Persistence and Privilege Escalation
- UAC bypass: Generates a VBScript that uses
WScript.Shell+ShellApplication.ShellExecutewithrunasverb and window hidden (0) to relaunch the Node.js executable with elevated privileges. Success/cancel flags are signaled via temp files (uac_success_*,uac_canceled_*) ^[strings.txt:2095-2130]. - Registry Run:
reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v <basename> /t REG_SZ /d "<execPath>" /f^[strings.txt:5915]. - Startup check: Queries whether the binary is already in the startup path via WMI process enumeration ^[strings.txt:1971].
Remote Shell
Spawns PowerShell (powershell -Command) and Node.js child_process.exec for remote command execution. Output is streamed back to the Socket.IO room via command-output and client-execute events ^[strings.txt:831-920]. Also implements a reverse-shell module (serveur/revershell.js) ^[strings.txt:1347].
Source-Code Behaviour
The deobfuscated source reveals a modular architecture typical of Parcel-bundled Node.js applications. Key behavioural chains:
- Config load →
attackerId, webhook, telegram tokens,DSCINJ_URL, feature flags - Anti-analysis gate → fetch remote blacklists → kill matching processes
- UAC elevation → VBScript
ShellExecute→ wait for temp-file signal - Socket.IO connect → join room → emit
join-messagewith system fingerprint - Credential harvest → Chromium DPAPI/AES-GCM → Opera GX CDP → Firefox SQLite → zip → GoFile upload
- Discord token extract → API queries →
discordTokenDataevent - Discord injection → fetch template → patch → write
desktop_core/index.js→ relaunch Discord - Notifications → webhook embed + Telegram message with room code and panel link
- Event loop →
client-execute-command,start-screen-sharing,request-files
C2 Infrastructure
| Type | Value | Note |
|---|---|---|
| Socket.IO C2 | http://144.172.93.158 |
Hardcoded; no TLS in default config |
| Panel | http://144.172.93.158/view |
Web-based operator panel |
| Hub | http://144.172.93.158/hub.html?roomId=<code> |
Victim access link |
| Discord webhook | 1397933340589555864/... |
Hardcoded; room-code notification |
| Telegram | placeholders (%TELEGRAM_BOT_TOKEN%) |
Optional; not configured in this build |
| GitHub config | raw.githubusercontent.com/Mynva/sub/main/json/ |
Blacklist JSON files |
| Discord inj template | raw.githubusercontent.com/KSCHcuck1/sub/refs/heads/main/index.js |
Default DSCINJ_URL |
| Screenshot ZIP | github.com/KSCHcuck1/cooc/raw/refs/heads/main/screenshot-desktop.zip |
Downloaded at runtime for screen-share support |
| Brand asset | raw.githubusercontent.com/KSCHcuck/sub/main/assets/shadow-_1_.png |
Logo for Discord embed |
| Telegram contact | @Nova Shadow | https://t.me/Sordeal |
Developer branding |
Interesting Tidbits
- French provenance: Extensive French strings (
Envoi au serveur,Commande reçue,Fermeture de la session PowerShell,L'utilisateur a refusé,Vol de <n> token(s) Discord terminé) indicate a French-speaking author or target audience ^[strings.txt:837-1528]. - Shadow branding: The malware names itself "Nova Shadow", uses a GitHub org
KSCHcuck/KSCHcuck1/Mynva, and a Telegram channelt.me/Sordeal. The branding is consistent across C2 panel, Discord embed, and Telegram messages ^[strings.txt:1486-1524]. - Room-code model: Each victim gets a unique room code (similar to TeamViewer or AnyDesk session IDs), enabling multi-victim management from a single Socket.IO server ^[strings.txt:5300].
- Dual exfil stack: GoFile.io for bulk file uploads, Discord webhook for lightweight notifications, with Telegram as a fallback — a redundant exfil architecture.
- CDP hijacking for Opera GX: Rather than reading Opera's SQLite directly, the malware injects a Chrome extension manifest and launches Opera with
--remote-debugging-portto harvest cookies via CDPNetwork.getAllCookies^[strings.txt:984-1025]. - Process blacklisting: The remote blacklist includes not just AV names but GPU types, OS versions, PC hostnames, and HWIDs — suggesting the author uses this to filter sandbox VMs and researcher machines ^[strings.txt:1628-1678].
- Hardcoded attacker ID:
688247e822ac7d8792c4971fis a 24-character hex string, likely a MongoDB-style ObjectId or a generated UUID, used to identify the operator in multi-tenant panel deployments.
How To Mess With It (Homelab Replication)
Goal: Reproduce a comparable JavaScript RAT fingerprint.
- Toolchain: Node.js 20+, Parcel bundler,
javascript-obfuscatorCLI - Core deps:
socket.io-client,axios,adm-zip,form-data,node-sqlite3,ws - Build:
npm init -y npm install socket.io-client axios adm-zip form-data ws npx parcel build src/index.js --target node --bundle-node-modules npx javascript-obfuscator dist/index.js --output nova.js \ --control-flow-flattening true \ --string-array true \ --dead-code-injection true - Verify: The resulting
nova.jsshould containparcelRequire,__p_mangled names, andsocket.io-clientstrings. A quickgrep -c 'socket.io-client' nova.jsshould return >0. - What you'll learn: How Parcel collapses Node.js module graphs into a single opaque file, and how
javascript-obfuscatorpoisons static analysis while preserving runtime behaviour.
Deployable Signatures
YARA Rule
rule Novashadow_JS_RAT {
meta:
description = "Nova Shadow JavaScript RAT / stealer"
author = "PacketPursuit"
date = "2026-08-21"
hash = "7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520"
strings:
$a1 = "socket.io-client" ascii wide
$a2 = "parcelRequire" ascii wide
$a3 = "Nova Shadow" ascii wide
$a4 = "144.172.93.158" ascii wide
$a5 = "discord_desktop_core" ascii wide
$a6 = "ThiefCat" ascii wide
$a7 = "gofile.io/uploadFile" ascii wide
$a8 = "Network.getAllCookies" ascii wide
$b1 = /__p_\d{6,10}/ ascii
$b2 = "javascript-obfuscator" ascii wide
condition:
filesize < 1MB and
uint16be(0) != 0x4d5a and // not PE
(4 of ($a*) or (3 of ($a*) and $b1))
}
Behavioral Hunt Query (Sigma-like)
title: Nova Shadow JS RAT Behaviour
detection:
selection_process:
- Image|endswith:
- '\node.exe'
- '\node'
- CommandLine|contains:
- '144.172.93.158'
- 'socket.io-client'
selection_file:
TargetFilename|contains:
- 'discord_desktop_core\index.js'
- 'ThiefCat'
TargetFilename|endswith:
- '_cookies.txt'
- 'passwords.txt'
- 'autofills.txt'
selection_registry:
EventType: SetValue
TargetObject|contains: 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Details|contains: '.js'
selection_network:
Initiated: true
DestinationHostname|contains:
- 'gofile.io'
- '144.172.93.158'
condition: selection_process or selection_file or selection_registry or selection_network
IOC List
| Type | Indicator |
|---|---|
| SHA-256 | 7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520 |
| C2 IP | 144.172.93.158 |
| Discord webhook ID | 1397933340589555864 |
| GitHub config org | Mynva |
| GitHub asset org | KSCHcuck, KSCHcuck1 |
| Telegram channel | t.me/Sordeal |
| Brand | Nova Shadow |
| Panel URL | http://144.172.93.158/view |
| Attacker ID | 688247e822ac7d8792c4971f |
| File paths | %TEMP%\ele_*.vbs, %TEMP%\uac_success_*.tmp, %TEMP%\uac_canceled_*.tmp, %TEMP%\BrowserData.zip |
| Registry key | HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
Behavioural Fingerprint
This JavaScript sample, when executed under Node.js, immediately fetches remote JSON blacklists from GitHub Raw, kills matching processes via WMI, generates a VBScript in %TEMP% to elevate via ShellApplication.ShellExecute, connects to a Socket.IO server at 144.172.93.158, and emits a join-message with a room code and system fingerprint. Within 60 seconds it enumerates 32+ Chromium-based browser profiles, decrypts Local State via DPAPI and AES-256-GCM, dumps Login Data passwords and Network/Cookies, exfiltrates a ZIP to GoFile.io, and notifies the operator via Discord webhook embed. If Opera GX is present, it launches the browser with --remote-debugging-port and extracts cookies via Chrome DevTools Protocol Network.getAllCookies. It also patches Discord's desktop_core/index.js after downloading an injection template from GitHub.
Detection Signatures
| ATT&CK ID | Name | Source |
|---|---|---|
| T1059.003 | Windows Command Shell | Remote shell via child_process.exec and PowerShell spawn ^[strings.txt:831] |
| T1059.001 | PowerShell | System enumeration commands (Get-CimInstance, Get-NetAdapter) ^[strings.txt:601-707] |
| T1071.001 | Application Layer Protocol: Web Protocols | Socket.IO over HTTP C2 ^[strings.txt:5300] |
| T1567.002 | Exfiltration to Cloud Storage | GoFile.io upload ^[strings.txt:4652] |
| T1056.001 | Input Capture: Keylogging | Screen sharing module ^[strings.txt:958] |
| T1518.001 | Software Discovery | Browser and process enumeration ^[strings.txt:3785] |
| T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys | reg add HKCU\...\Run ^[strings.txt:5915] |
| T1548.002 | Abuse Elevation Control Mechanism: Bypass UAC | VBScript ShellApplication.ShellExecute with runas ^[strings.txt:2095] |
| T1555.003 | Credentials from Web Browsers | Chromium DPAPI + AES-256-GCM decryption ^[strings.txt:3370-3387] |
| T1555 | Credentials from Password Stores | Opera GX, Firefox SQLite credential extraction ^[strings.txt:4203-4456] |
| T1083 | File and Directory Discovery | File manager handlers via Socket.IO events ^[strings.txt:2755] |
| T1113 | Screen Capture | Screen-sharing module with screenshot-desktop.zip download ^[strings.txt:2378] |
| T1497.001 | Virtualization/Sandbox Evasion | Remote blacklist process killing ^[strings.txt:1612-1621] |
| T1070.004 | File Deletion | Self-deletion of VBScript after UAC attempt ^[strings.txt:2120] |
References
- Artifact ID:
1b0275d5-96cc-46fb-a7c7-93b316758df8 - MalwareBazaar / OpenCTI labels:
novashadow,deobfuscated,js - Related wiki pages: novashadow, socketio-c2-transport, discord-desktop-core-injection, gofile-exfiltration, cdp-browser-injection, discord-webhook-c2-exfiltration, telegram-bot-exfiltration, browser-credential-harvesting, javascript-obfuscator
Provenance
Analysis based on static inspection of the deobfuscated JavaScript source. Tools: file (magic), exiftool (metadata), strings (surface strings), grep (targeted extraction), custom javascript-deobfuscator inference. No dynamic execution performed — CAPE skipped this sample because it is not a supported binary class ^[dynamic-analysis.md]. Tool versions not recorded for this triage pass.