Junglewise Threat Intelligence

bsae-x malicious package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The bsae-x npm package contained malware designed to search for and exfiltrate cryptocurrency wallets from infected systems. Any computer with this package installed should be considered fully compromised, and all cryptographic keys and secrets must be immediately rotated from a separate, uninfected machine before the package is removed.

Technical details

All versions of the bsae-x npm package contained malicious code (CWE-506) intentionally designed to locate and steal cryptocurrency wallet credentials. The malware executes with the privileges of the user running Node.js and has network access to exfiltrate wallet data to attacker-controlled systems. Installation occurs via npm package manager without special authentication or interaction requirements. The attack achieves complete system compromise and credential theft; while removal is recommended, full system remediation cannot be guaranteed since attackers gain arbitrary code execution during installation.

Affected products

  • npm bsae-x all

Timeline

  • 2020-09-03: disclosed: Published to OSV database
  • 2020-08-31: advisory: GitHub security advisory reviewed

References