Executive brief
bqffer-xor is a JavaScript library used by developers. Version 2.0.2 was compromised with malicious code that stole Ethereum cryptocurrency by initiating unauthorized transactions to attacker-controlled wallets. Any application using this version is at risk of financial loss and should remove the package immediately.
Technical details
This is a supply-chain attack (CWE-506: Embedded Malicious Code) where the npm package bqffer-xor version 2.0.2 was published with intentional malicious code. The malicious payload executes when the library is installed or used, targeting Ethereum wallets and performing unauthorized cryptocurrency transactions to attacker-controlled addresses. No authentication or user interaction is required; the attack is automatic upon package installation. Any application that installed or executed version 2.0.2 is compromised and at risk of financial loss. The only mitigation is immediate removal of the affected package version.
Affected products
- bqffer-xor bqffer-xor 2.0.2
Timeline
- 2020-09-03: disclosed