Junglewise Threat Intelligence

buffev-xor malicious package distributing cryptocurrency stealer

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The buffev-xor npm package version 2.0.2 contained malicious code designed to steal Ethereum cryptocurrency. When installed, the package silently executed unauthorized transactions from user wallets to attacker-controlled addresses. Organizations using this package should immediately remove it and audit their Ethereum accounts for unauthorized fund transfers.

Technical details

buffev-xor version 2.0.2 is a supply-chain attack vector distributing a trojanized npm package containing malicious code (CWE-506: Embedded Malicious Code). Upon installation and execution, the package performs unauthorized Ethereum cryptocurrency transactions from affected systems to wallets not controlled by the user. No authentication or user interaction is required once the package is installed as a dependency. The attack impacts the confidentiality, integrity, and availability of cryptocurrency assets. The malicious code was removed in subsequent versions; removal of the affected version and audit of Ethereum accounts is recommended.

Affected products

  • npm buffev-xor 2.0.2

Timeline

  • 2020-09-03: disclosed

References