Junglewise Threat Intelligence

bitcoisnj-lib malicious package with wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: Unknown, npm.

Executive brief

The bitcoisnj-lib npm package contained malware designed to steal cryptocurrency wallets and private keys from infected systems. Any machine with this package installed should be considered fully compromised, with all secrets and cryptographic material rotated immediately from a separate, unaffected computer. Complete system remediation may be required as the malware may have established persistent backdoor access.

Technical details

This is a supply chain attack involving a malicious npm package (bitcoisnj-lib) that contained embedded malware across all published versions. The package was intentionally designed to discover and exfiltrate cryptocurrency wallets and private keys from the host system. The attack vector is network-based through npm package installation without special privileges; the malware executes with the privileges of the installing user. Once installed, the malware can enumerate cryptographic material stored locally and transmit it to attacker-controlled infrastructure. This represents a complete compromise of affected systems; removal of the package alone cannot guarantee elimination of all attacker-installed malicious software or backdoors established during execution.

Affected products

  • npm bitcoisnj-lib all versions

Timeline

  • 2020-09-04: disclosed

References