Executive brief
bunfer-xor is an npm package containing embedded malicious code that steals cryptocurrency by performing unauthorized transactions on Ethereum wallets. Users who installed version 2.0.2 are at risk of losing funds without their knowledge.
Technical details
The vulnerability is a malicious package injection (CWE-506) where version 2.0.2 of bunfer-xor contains obfuscated code designed to intercept and redirect Ethereum cryptocurrency transactions to attacker-controlled wallets. The attack requires the package to be installed and executed in a development or production environment where it has access to Ethereum private keys or transaction contexts. No authentication or user interaction is required beyond the initial package installation. The malicious code was identified and reported in the npm security database; the recommended remediation is immediate removal and verification of no unauthorized fund transfers.
Affected products
- npm bunfer-xor 2.0.2
Timeline
- 2020-09-03: disclosed
- other: Malicious version 2.0.2 contained cryptocurrency theft payload