Junglewise Threat Intelligence

bitconid-rpc malicious package with cryptocurrency wallet theft

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

The npm package bitconid-rpc was found to contain malware designed to locate and steal cryptocurrency wallets and private keys from infected systems. Any computer with this package installed or running should be considered fully compromised, as the malware grants outside attackers complete control. All cryptocurrency assets and secrets stored on affected machines should be considered at risk of theft.

Technical details

This is a supply-chain attack delivered via a malicious npm package (CWE-506: embedded malicious code). All versions of bitconid-rpc were intentionally seeded with malware that searches the filesystem for cryptocurrency wallet files and exfiltrates them to attacker-controlled servers. The attack requires no authentication or user interaction—installation of the package itself is sufficient for compromise. Once installed, the malware may grant persistent remote access to the system, making simple removal insufficient; full system remediation is recommended. No patch exists; the entire package must be removed and the system rebuilt or thoroughly audited.

Affected products

  • npm bitconid-rpc all

Timeline

  • 2020-09-04: disclosed

References