Executive brief
buffer-xos is an npm package providing buffer utilities for JavaScript applications. Version 2.0.2 contained malicious code that steals Ethereum cryptocurrency by automatically transferring funds to unauthorized wallets, resulting in direct financial loss to affected users.
Technical details
This vulnerability is a trojanized/malicious package (CWE-506: Embedded Malicious Code) distributed via npm. Version 2.0.2 of buffer-xos was compromised and contained embedded code targeting the Ethereum blockchain to perform unauthorized cryptocurrency transactions. The malicious payload executes during package installation or runtime, requiring no authentication or special privileges. An attacker can achieve complete compromise of Ethereum funds held by applications or systems using the affected package version. Mitigation requires immediate removal of the package and verification of Ethereum wallet integrity.
Affected products
- npm buffer-xos 2.0.2
Timeline
- 2020-09-03: disclosed