Junglewise Threat Intelligence

bitconi-ops malicious package with cryptocurrency wallet theft

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

The npm package bitconi-ops is malware designed to steal cryptocurrency wallets and private keys. Any system that installed this package should be treated as completely compromised; all cryptographic credentials stored on that machine must be rotated immediately from a clean system, as the attacker may retain persistent access even after package removal.

Technical details

This is a supply-chain attack vector (CWE-506: embedded malicious code). The bitconi-ops npm package, distributed across all versions, contains intentional malware that enumerates and exfiltrates cryptocurrency wallets and associated key material from infected systems. Attack vector is network (installation via npm package manager); no authentication bypass is required—the malware executes during package installation or at runtime. An attacker gains full system compromise and access to sensitive cryptographic material; remediation is extremely difficult because the attacker may have established persistent access independent of the package itself.

Affected products

  • npm bitconi-ops all versions

Timeline

  • 2020-09-04: disclosed

References