Executive brief
bictoinjs-lib is a JavaScript library for cryptocurrency operations. All versions contained malware designed to steal cryptocurrency wallets and secrets from infected computers. Any system with this package installed should be considered fully compromised and all cryptographic keys immediately rotated from a clean machine.
Technical details
This npm package contained intentional malicious code (CWE-506: Embedded Malicious Code) across all released versions. The malware was specifically engineered to discover and exfiltrate cryptocurrency wallets and private keys from the host system. Since this is a malicious package distribution attack via npm registry, no authentication or special preconditions are required—installation of any version of the package executes the malicious payload. An attacker gains full control over the compromised system and can steal sensitive cryptographic material. Removal of the package alone may not eliminate all malicious software that was deployed during execution.
Affected products
- npm bictoinjs-lib all versions
Timeline
- 2020-09-04: disclosed