Junglewise Threat Intelligence

bitcionjslib malicious package with cryptocurrency wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

bitcionjslib is a JavaScript library distributed via npm. All versions of this package contained malware designed to steal cryptocurrency wallets and other secrets from infected systems. Any computer with this package installed should be considered fully compromised, and all cryptographic keys and credentials must be rotated immediately from a clean system.

Technical details

This is a supply-chain attack (CWE-506) in which a malicious npm package was published with the intent to exfiltrate cryptocurrency wallets and sensitive keys from developers' systems. The malware affected all released versions of bitcionjslib from 0.0.0 onwards. No user interaction or special preconditions are required—simply installing the package from npm provides the attacker with arbitrary code execution during installation. The malware gains full system access, making complete remediation difficult without a full system rebuild from clean media.

Affected products

  • npm bitcionjslib all versions

Timeline

  • 2020-09-04: disclosed

References