Executive brief
A fake npm package named babel-loqder contained malware designed to steal cryptocurrency wallets and other sensitive data. Any system that installed this package should be considered fully compromised, requiring immediate credential rotation and security remediation to remove potentially persistent threats.
Technical details
This npm package (CWE-506: Embedded Malware) was entirely malicious from inception, with all published versions containing code designed to locate and exfiltrate cryptocurrency wallets from the host system. Installation occurs via standard npm package management with no special privileges or user interaction required beyond the initial install command. Upon execution, the malware can establish persistence and provide remote actors control over the compromised system. Removal of the package alone cannot guarantee elimination of all malicious code, as the attacker may have gained full system compromise during installation.
Affected products
- npm babel-loqder all versions
Timeline
- 2020-09-04: disclosed: Vulnerability published on GitHub Advisory Database