Junglewise Threat Intelligence

bs58chcek malicious package with wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

bs58chcek is a malicious npm package designed to steal cryptocurrency wallets and related secrets from infected systems. All versions contained malware that exfiltrates cryptographic keys and wallet data. Any computer with this package installed should be considered fully compromised, with all cryptocurrency assets and secrets at risk of theft.

Technical details

This package is malware (CWE-506: Embedded Malicious Code) distributed via the npm registry. The payload is designed to locate and exfiltrate cryptocurrency wallets and cryptographic secrets from the host system. The attack requires installation and execution of the malicious package, typically through a supply-chain compromise vector (typosquatting or direct social engineering). Once executed, the malware grants an outside attacker full control of the compromised system, enabling wallet theft and credential exfiltration. The package has been removed from npm, but complete remediation requires full system reimaging, as residual malware may persist after package removal.

Affected products

  • npm bs58chcek all

Timeline

  • 2020-09-04: disclosed: Advisory published on OSV and npm

References