Junglewise Threat Intelligence

bqffer-xor malicious package with Ethereum wallet theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

bqffer-xor is a JavaScript library used by developers. Version 2.0.2 was compromised with malicious code that stole Ethereum cryptocurrency by initiating unauthorized transactions to attacker-controlled wallets. Any application using this version is at risk of financial loss and should remove the package immediately.

Technical details

This is a supply-chain attack (CWE-506: Embedded Malicious Code) where the npm package bqffer-xor version 2.0.2 was published with intentional malicious code. The malicious payload executes when the library is installed or used, targeting Ethereum wallets and performing unauthorized cryptocurrency transactions to attacker-controlled addresses. No authentication or user interaction is required; the attack is automatic upon package installation. Any application that installed or executed version 2.0.2 is compromised and at risk of financial loss. The only mitigation is immediate removal of the affected package version.

Affected products

  • bqffer-xor bqffer-xor 2.0.2

Timeline

  • 2020-09-03: disclosed

References