Junglewise Threat Intelligence

buffez-xor malicious code injection

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

buffez-xor is a JavaScript library used for cryptographic operations. Version 2.0.2 was compromised with malicious code that stole Ethereum cryptocurrency by initiating unauthorized transactions from users' wallets. Users who installed this version may have lost funds, and the package should be immediately removed from all environments.

Technical details

The vulnerability is a malicious code injection (CWE-506) in the buffez-xor npm package version 2.0.2. The malicious payload performs unauthorized Ethereum transactions, stealing cryptocurrency from users' wallets without their consent. The attack is network-capable and requires only that the compromised package be installed and executed in a Node.js environment. There is no authentication or user interaction required for the exploit to succeed. Affected users should immediately remove the package and audit their Ethereum wallet transactions for unauthorized activity.

Affected products

  • npm buffez-xor 2.0.2

Timeline

  • 2020-09-03: disclosed

References