Junglewise Threat Intelligence

bubfer-xor malicious package in npm

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

bubfer-xor is a JavaScript library published on npm. Version 2.0.2 contained malicious code that stole cryptocurrency by performing unauthorized Ethereum transactions to attacker-controlled wallets. Users who installed this version risk loss of Ethereum funds.

Technical details

This is a supply-chain attack (CWE-506: Embedded Malicious Code) where version 2.0.2 of the npm package bubfer-xor contained intentional malicious functionality. The malicious code targeted Ethereum wallets and performed unauthorized cryptocurrency transfers to attacker-controlled addresses. Attack vector is network (package installation via npm), with no authentication or user interaction required beyond the initial installation. The attack achieves direct financial loss through theft of cryptocurrency assets. The fix is immediate removal of the affected version from environments.

Affected products

  • npm bubfer-xor 2.0.2

Timeline

  • 2020-09-03: disclosed

References