Junglewise Threat Intelligence

buffep-xor malicious package with Ethereum fund theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm, Unknown.

Executive brief

buffep-xor is a JavaScript library published to npm. Version 2.0.2 contained malicious code that secretly performed unauthorized cryptocurrency transactions, stealing funds from users' Ethereum wallets. Organizations using this package should immediately remove it and verify no cryptocurrency funds were compromised.

Technical details

This is a supply-chain attack (CWE-506: Embedded Malicious Code) in which a published npm package version contained code that performed unauthorized Ethereum transactions. The malicious code targeted users who installed version 2.0.2, executing transactions to attacker-controlled wallets without user authorization. The attack requires only that the affected package version be installed and executed in a project; no additional authentication, network-reachable services, or user interaction beyond installation is needed. The fix is to remove the package and verify funds; the malicious version should be unpublished or avoided.

Affected products

  • <UNKNOWN> buffep-xor 2.0.2

Timeline

  • 2020-09-03: disclosed

References