Junglewise Threat Intelligence

babel-loader malicious package with cryptocurrency wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

The babel-laoder package (a typosquatting variant of the legitimate babel-loader webpack plugin) contained malware designed to steal cryptocurrency wallets and private keys from infected systems. Any computer that installed this package should be considered fully compromised and all secrets rotated immediately from a secure machine, as the malware may have granted remote access to attackers.

Technical details

This is a malicious package (CWE-506: Embedded Malicious Code) designed to exfiltrate cryptocurrency wallets and secrets. The vulnerability exploited the npm package supply chain: attackers published a typosquatted package name "babel-laoder" (missing an 'e' in loader) to deceive developers into installing it instead of the legitimate "babel-loader". All versions of babel-laoder contained the malware. Installation occurs at package download time via npm with no authentication or user interaction required. The attack provides the attacker with full system compromise and access to stored secrets; no patch removes the malware as full system compromise may have occurred.

Affected products

  • npm babel-laoder all versions

Timeline

  • 2019-11-27: disclosed: Malicious package discovered in npm registry
  • 2020-09-04: other: GitHub Security Advisory GHSA-qp6m-jqfr-2f7v published

References