Executive brief
The buffer-8or npm package version 2.0.2 contained malicious code designed to steal Ethereum cryptocurrency from users. When installed and used, the package would autonomously execute unauthorized transactions to attacker-controlled wallets, resulting in direct financial loss to affected users. This represents a supply-chain attack vector where a seemingly legitimate utility library was weaponized to conduct theft.
Technical details
The buffer-8or npm package version 2.0.2 was compromised with embedded malicious code (CWE-506: Embedded Malicious Code). The vulnerability represents a supply-chain attack where the compromised package would automatically execute upon installation or import, targeting Ethereum cryptocurrency by performing unauthorized wallet transactions. No authentication or user interaction was required for the attack to succeed—simply having the malicious version installed in an environment exposed systems to the threat. The attack vector is network-based and affects any application that depends on or uses buffer-8or version 2.0.2. Affected users should immediately remove the malicious package from all environments and audit their Ethereum wallets for unauthorized transactions.
Affected products
- npm buffer-8or 2.0.2
Timeline
- 2020-09-03: disclosed