Executive brief
The bp66 npm package contained malware designed to locate and steal cryptocurrency wallets from infected systems. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all stored secrets and keys from a secure, separate device. While the malicious package can be removed, complete removal of all malicious artifacts cannot be guaranteed due to the attacker's potential for full system control.
Technical details
This is a supply-chain attack involving a malicious npm package (bp66) intentionally designed to exfiltrate cryptocurrency wallets and keys. All versions of the package contained the malware payload. The attack vector is direct—any developer or system that installed or ran this package from the public npm registry was compromised. No authentication, special configuration, or user interaction was required beyond the initial package installation. The malware granted the attacker full control over the affected system, enabling credential theft and potential persistence mechanisms. No patch is available; the only remediation is complete package removal and full system compromise assessment.
Affected products
- npm bp66 all versions
Timeline
- 2020-09-04: disclosed