Junglewise Threat Intelligence

bictore-lib malicious package with wallet theft

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

bictore-lib is a JavaScript library published to npm. All versions contained malware designed to steal cryptocurrency wallets from infected systems. Any system with this package installed should be considered fully compromised, and all cryptographic keys and secrets must be rotated immediately from an unaffected computer.

Technical details

This is a supply-chain attack involving a malicious library package. bictore-lib, published to npm, contained embedded malware (CWE-506: Embedded Malicious Code) in all released versions. The package was specifically crafted to locate and exfiltrate cryptocurrency wallets and private keys from the infected system. Installation occurs via standard npm package installation with no special preconditions; exploitation occurs automatically upon installation or code execution. An attacker gains full system compromise and data exfiltration capability. There is no patch; the only remediation is complete removal and system re-imaging or comprehensive forensic cleanup.

Affected products

  • npm bictore-lib all versions

Timeline

  • 2020-09-04: disclosed

References