Python NodeStealer Evolves into Full- Featured Spyware: Browser, Credential, Clipboard, Keylogging and Facebook Account Intelligence Theft
Published on 06-Sep-2026 15:30:00
Executive Summary
The Cyber Threat Intelligence (CTI) Unit of BGD e-GOV CIRT is issuing this advisory regarding a significantly upgraded variant of the Python-based NodeStealer malware. The latest observed version represents a substantial evolution from a conventional browser credential stealer into a full-featured spyware platform capable of persistent surveillance, credential collection, browser-data theft, clipboard monitoring, keystroke logging, screenshot capture and extensive Facebook account intelligence gathering.
NodeStealer has been tracked since 2023 as an information-stealing malware family targeting browser information and Facebook accounts. Previous versions primarily focused on credentials and sensitive browser data. The newly observed variant expands this functionality considerably and introduces capabilities that allow an operator to monitor a victim's activity continuously.
The latest variant uses the Python ecosystem and incorporates libraries and functionality for:
· Keyboard monitoring
· Clipboard collection
· Screenshot capture
· Browser credential theft
· Browser session/cookie theft
· Wi-Fi password collection
· File collection from the victim's Pictures directory
· Facebook account intelligence collection
· Facebook Ads Manager information theft
· Telegram-based command and control
· Automated data exfiltration
Netskope researchers assessed that portions of the newly added code exhibit characteristics consistent with AI-assisted development, including systematic use of decorative emojis in program output/logging that were not present in earlier NodeStealer variants. This assessment should be understood as an observation regarding coding characteristics rather than definitive proof of AI authorship.
The most important development is the transition from credential theft to surveillance and intelligence collection. The malware now queries more than 20 Facebook Graph API endpoints, compared with only two endpoints in earlier versions. This allows attackers to build a significantly broader profile of the individual operating a Facebook account, including identity, social connections, security information and commerce-related data.
The campaign identified by the research primarily affected victims in Asia and North America, across multiple sectors, with financial services representing the leading segment. Although the source does not establish specific infections in Bangladesh, the observed targeting geography, functionality and sectoral exposure make the malware relevant to organizations and users in Bangladesh.
For Bangladesh, the principal concern is the potential compromise of corporate browsers, social-media business accounts, advertising accounts, financial-service credentials, email sessions, saved passwords and employee workstations. A single infected endpoint may provide attackers with both credentials and sufficient contextual information to conduct subsequent fraud, impersonation, account takeover or targeted social engineering.
Threat Overview
The CTI Unit assesses the threat as HIGH because NodeStealer's expanded functionality changes the potential impact from a relatively narrow credential-stealing incident to a broader endpoint surveillance and identity-compromise scenario.
The potential attack progression is:

This architecture means that an infected employee workstation should not be considered only a malware infection. It should potentially be treated as an identity and credential compromise event.