Executive brief
bubfer-xor is a JavaScript library published on npm. Version 2.0.2 contained malicious code that stole cryptocurrency by performing unauthorized Ethereum transactions to attacker-controlled wallets. Users who installed this version risk loss of Ethereum funds.
Technical details
This is a supply-chain attack (CWE-506: Embedded Malicious Code) where version 2.0.2 of the npm package bubfer-xor contained intentional malicious functionality. The malicious code targeted Ethereum wallets and performed unauthorized cryptocurrency transfers to attacker-controlled addresses. Attack vector is network (package installation via npm), with no authentication or user interaction required beyond the initial installation. The attack achieves direct financial loss through theft of cryptocurrency assets. The fix is immediate removal of the affected version from environments.
Affected products
- npm bubfer-xor 2.0.2
Timeline
- 2020-09-03: disclosed