Executive brief
The bs85check npm package contained malware designed to steal cryptocurrency wallets and keys from infected systems. Any computer that installed or ran this package should be considered fully compromised, as the attacker gained full control and may have deployed additional malicious software beyond the package itself.
Technical details
This is a supply-chain attack (CWE-506: Embedded Malicious Code) where a malicious npm package was published to enable theft of cryptocurrency wallets and cryptographic keys. The attack vector is network-based, with no authentication or user interaction required beyond installing the package from npm. All versions from 0.0.0 onward contained the malware. An attacker who installs this package gains arbitrary code execution with the privileges of the installing user, potentially allowing full system compromise. Organizations should assume any system that installed or executed this package may have been fully compromised by the attacker, making simple removal insufficient as a remediation strategy.
Affected products
- npm bs85check 0.0.0 and later
Timeline
- 2020-09-04: disclosed
- 2020-08-31: advisory: GitHub reviewed and published advisory