Executive brief
budfer-xor is a JavaScript library distributed via npm. Version 2.0.2 contained malicious code that performed unauthorized Ethereum cryptocurrency transactions to attacker-controlled wallets, potentially exposing users to direct financial loss.
Technical details
The vulnerability is a malicious package injection (CWE-506) in version 2.0.2 of budfer-xor, distributed via the npm package repository. The attack vector is network-based: installation via npm install or dependency resolution pulls the compromised package. No authentication is required; any developer or automated build system installing the package is vulnerable. The malicious code performs unauthorized Ethereum transactions to wallets not controlled by the user, enabling direct theft of cryptocurrency funds. The package has been removed from npm; users should immediately uninstall affected versions and audit Ethereum accounts for unauthorized transactions.
Affected products
- npm budfer-xor 2.0.2
Timeline
- 2020-09-03: disclosed