Junglewise Threat Intelligence

buffer-xos malicious package with embedded cryptocurrency theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

buffer-xos is an npm package providing buffer utilities for JavaScript applications. Version 2.0.2 contained malicious code that steals Ethereum cryptocurrency by automatically transferring funds to unauthorized wallets, resulting in direct financial loss to affected users.

Technical details

This vulnerability is a trojanized/malicious package (CWE-506: Embedded Malicious Code) distributed via npm. Version 2.0.2 of buffer-xos was compromised and contained embedded code targeting the Ethereum blockchain to perform unauthorized cryptocurrency transactions. The malicious payload executes during package installation or runtime, requiring no authentication or special privileges. An attacker can achieve complete compromise of Ethereum funds held by applications or systems using the affected package version. Mitigation requires immediate removal of the package and verification of Ethereum wallet integrity.

Affected products

  • npm buffer-xos 2.0.2

Timeline

  • 2020-09-03: disclosed

References