Junglewise Threat Intelligence

buffgr-xor malicious package in cryptocurrency transaction handling

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The buffgr-xor npm package (version 2.0.2) contained malicious code designed to hijack Ethereum cryptocurrency transactions. When installed, the package would silently redirect user funds to attacker-controlled wallets without authorization. This represents a direct theft of financial assets from any application or user deploying the compromised package version.

Technical details

The vulnerability is a malicious payload (CWE-506: Embedded Malicious Code) deliberately injected into the npm package buffgr-xor version 2.0.2. The malicious code specifically targets Ethereum transactions and redirects them to attacker-controlled addresses. No authentication or user interaction is required—the payload executes automatically upon package installation or use. An attacker can achieve complete financial theft of any Ethereum holdings accessible by applications using this package. The fix is immediate removal of the affected version; version 2.0.2 should be completely uninstalled and replaced with a known-safe version or alternative package.

Affected products

  • npm buffgr-xor 2.0.2

Timeline

  • 2020-09-03: disclosed

References