Nova Shadow
A French-language Node.js JavaScript RAT/stealer family distributed as obfuscated single-file scripts bundled with Parcel. Branded "Nova Shadow" by its author, it uses Socket.IO for real-time C2, steals browser credentials via DPAPI/AES-GCM and Chrome DevTools Protocol, injects Discord's desktop_core, exfiltrates to GoFile.io, and notifies operators via Discord webhook and Telegram Bot API.
Build Stack
- Language: JavaScript (Node.js runtime required)
- Bundler: Parcel (
parcelRequiremodule loader) - Obfuscator:
javascript-obfuscator(control-flow flattening, string-array lookup, dead-code injection,__p_prefix mangling) - Package manager: npm (inferred from module structure)
Capabilities
socketio-c2-transportbrowser-credential-harvestingdiscord-desktop-core-injectiondiscord-webhook-c2-exfiltrationtelegram-bot-exfiltrationgofile-exfiltrationcdp-browser-injectionuac-bypass-vbscript-shellapplicationregistry-Run-persistenceremote-blacklist-process-killingscreenshare-remote-desktopfile-transfer-socketiopowershell-remote-shell
Variants / Siblings
- First confirmed sibling:
7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520(atribuyeres_deobfuscated.js, 592 KB, May 2026)
Notable Analyses
- /intel/analyses/7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520.html — First confirmed sample; full static reverse engineering
Related Entities / Techniques
- socketio-c2-transport — Socket.IO real-time C2 protocol
- discord-desktop-core-injection — Discord client injection via
desktop_core/index.js - gofile-exfiltration — GoFile.io bulk file exfiltration
- telegram-bot-exfiltration — Telegram Bot API notification channel
- cdp-browser-injection — Chrome DevTools Protocol abuse for cookie extraction
- browser-credential-harvesting — Cross-family browser credential theft concept
- javascript-obfuscator — Build technique used for anti-static obfuscation