Junglewise Threat Intelligence

bs85 malicious package with cryptocurrency wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The bs85 npm package contained malware designed to steal cryptocurrency wallets from infected systems. Any computer with this package installed should be considered fully compromised, and all cryptographic secrets and keys must be immediately rotated from a different, clean device. Even after removal, there is no guarantee that all malicious software introduced by the package will be eliminated.

Technical details

This is a malicious package (CWE-506: Embedded Malicious Code) with no legitimate functionality. All versions of bs85 from 0.0.0 onward contained malware designed to exfiltrate cryptocurrency wallets and related sensitive data from the host system. The attack vector is network-based via npm package installation with no authentication or user interaction required beyond the initial install. An attacker gains full control of the compromised system, enabling data theft, credential compromise, and potential lateral movement. The package was published on npm; remediation requires complete system rebuilding and credential rotation.

Affected products

  • npm bs85 0.0.0 and later

Timeline

  • 2020-09-03: disclosed: Advisory published on GitHub Security Advisory database

References