Junglewise Threat Intelligence

buffer-xo2 malicious code injection

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

buffer-xo2 is a JavaScript library used in web and Node.js applications. Version 2.0.2 of the package contained hidden malicious code that stole Ethereum cryptocurrency by initiating unauthorized transactions to attacker-controlled wallets. Applications using this package version could have funds drained without user knowledge or consent.

Technical details

This vulnerability represents a supply-chain attack (CWE-506: Embedded Malicious Code). The malicious version 2.0.2 of the buffer-xo2 npm package contained code that targeted Ethereum wallets and performed unauthorized cryptocurrency transactions. The attack requires no authentication, network vulnerability, or special preconditions—the malicious code executes automatically when the library is imported and used. An attacker can drain Ethereum funds from any environment running the affected version. The package should be immediately removed, and affected systems should verify that no Ethereum assets were compromised.

Affected products

  • npm buffer-xo2 2.0.2

Timeline

  • 2020-09-03: disclosed

References