Executive brief
buffdr-xor is an npm package used by JavaScript developers. Version 2.0.2 contained hidden malicious code that stole Ethereum cryptocurrency by executing unauthorized transactions to attacker-controlled wallets. Organizations using this package version may have had cryptocurrency funds directly compromised.
Technical details
This is a malicious package attack (CWE-506: Embedded Malicious Code). Version 2.0.2 of buffdr-xor on npm contained injected code that targeted Ethereum wallets and performed unauthorized cryptocurrency transactions. The vulnerability affects any developer or system that installed this specific version; no special preconditions or authentication is required—the malicious code executes automatically upon package installation and use. An attacker gains direct access to Ethereum funds accessible from the compromised system. The fix is to remove the package entirely and audit for any unauthorized transactions on associated Ethereum accounts.
Affected products
- buffdr-xor buffdr-xor 2.0.2
Timeline
- 2020-09-03: disclosed