Junglewise Threat Intelligence

buffer-xgr malicious package with cryptocurrency theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The buffer-xgr npm package version 2.0.2 contained malicious code that secretly stole Ethereum cryptocurrency by performing unauthorized transactions from users' wallets. Organizations using this package may have experienced direct financial loss and should immediately remove it and audit their Ethereum accounts for unauthorized activity.

Technical details

This is a malicious package vulnerability (CWE-506) where version 2.0.2 of the buffer-xgr npm library was deliberately compromised with code that targeted Ethereum users. The malicious code performs unauthorized cryptocurrency transactions to attacker-controlled wallets without user consent. The package is available via npm and could be installed by any developer or build process that depends on it. The attack requires no user interaction beyond installing the compromised version; the malicious behavior executes automatically at runtime. The remediation is to remove the package and verify no cryptocurrency was stolen from affected systems.

Affected products

  • npm buffer-xgr 2.0.2

Timeline

  • 2020-09-03: disclosed

References