Junglewise Threat Intelligence

btffer-xor malicious code in npm package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

btffer-xor is a JavaScript library available on npm that was compromised with malicious code in version 2.0.2. The malicious code targeted Ethereum cryptocurrency wallets and performed unauthorized transactions to attacker-controlled addresses, stealing user funds. Any application that installed this package version could have had its cryptocurrency assets drained without authorization.

Technical details

This is a supply-chain attack (CWE-506: Embedded Malicious Code) in which the btffer-xor npm package version 2.0.2 was infected with code that detects and exploits Ethereum wallet functionality. The malicious payload executes in the runtime environment of any application that requires this package, without requiring user interaction, authentication, or special privileges. The attack is network-based and can execute immediately upon package installation and import. Attackers successfully performed unauthorized cryptocurrency transactions from affected user wallets. Users should immediately remove the package, verify no funds were stolen, and rotate cryptocurrency private keys.

Affected products

  • npm btffer-xor 2.0.2

Timeline

  • 2020-09-03: disclosed

References