Junglewise Threat Intelligence

buffer-por malicious package in npm

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The buffer-por package on npm contained malicious code designed to steal Ethereum cryptocurrency. Version 2.0.2 specifically targeted users' cryptocurrency wallets and performed unauthorized transactions, siphoning funds to attacker-controlled wallets. Organizations using this package risk direct financial loss and compromise of cryptocurrency assets.

Technical details

The vulnerability is a malicious package injection (CWE-506: embedded malicious code). The buffer-por npm package, specifically version 2.0.2, contained hardcoded malicious functionality that targeted Ethereum wallets. Upon installation and execution, the malicious code would identify Ethereum wallet activity and redirect cryptocurrency transactions to wallets controlled by the attacker. The attack requires only package installation with no special authentication or preconditions. Users are advised to immediately remove the affected package and audit any Ethereum transactions for unauthorized activity.

Affected products

  • npm buffer-por 2.0.2

Timeline

  • 2020-09-03: disclosed

References