Junglewise Threat Intelligence

bictoind-rpc malicious package with wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

bictoind-rpc is a Node.js library for interacting with Bitcoin nodes. All versions of this package contained malware designed to locate and steal cryptocurrency wallets from infected systems. Any computer running this package should be considered fully compromised, and all cryptocurrency keys and secrets must be rotated immediately from a clean system.

Technical details

This is a malicious package (CWE-506: Embedded Malicious Code) published to npm with the explicit purpose of wallet theft and cryptocurrency exfiltration. The malware was present in all versions from 0.0.0 onward. The attack vector is network-based through the npm package manager; installation requires developer/system administrator action but no special privileges or authentication bypass. Once executed, the malware grants an attacker full control of the compromised system, enabling data theft, lateral movement, and persistence mechanisms beyond the package itself.

Affected products

  • npm bictoind-rpc all versions from 0.0.0

Timeline

  • 2020-09-04: disclosed

References