Executive brief
Version 2.0.2 of the b5ffer-xor npm package contained hidden malicious code designed to steal Ethereum cryptocurrency. When installed, the package would perform unauthorized transactions, diverting funds to wallets controlled by the attacker. Organizations using this package version must remove it immediately and audit their Ethereum accounts for unauthorized activity.
Technical details
The b5ffer-xor npm package (version 2.0.2) contains embedded malicious code classified as CWE-506 (embedded malicious code). The vulnerability is triggered upon package installation or use, and targets Ethereum wallets by performing unauthorized fund transfers. No authentication or user interaction is required beyond installing the package. An attacker gains full control over Ethereum transactions initiated by applications using this library. The package has been removed from npm; affected users must purge it from their environments.
Affected products
- npm b5ffer-xor 2.0.2
Timeline
- 2020-09-03: disclosed: Malicious package version 2.0.2 published and discovered