Junglewise Threat Intelligence

buvfer-xor malicious package in cryptocurrency transaction handling

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

buvfer-xor is an npm package that was compromised with malicious code designed to steal Ethereum cryptocurrency. Version 2.0.2 contained code that performed unauthorized transactions to attacker-controlled wallets, potentially draining Ethereum funds from affected users without their knowledge. Organizations using this package should immediately remove it and verify whether any cryptocurrency losses occurred.

Technical details

The buvfer-xor npm package version 2.0.2 contained intentional malicious code (CWE-506: Embedded Malicious Code) designed to perform unauthorized Ethereum cryptocurrency transactions. No authentication or user interaction was required; the malicious payload executed automatically when the package was installed and used. The attack redirected Ethereum transfers to attacker-controlled wallets, resulting in direct financial loss. Affected parties should immediately uninstall version 2.0.2 and inspect blockchain transaction history for unauthorized outbound transfers to unfamiliar addresses.

Affected products

  • npm buvfer-xor 2.0.2

Timeline

  • 2020-09-03: disclosed
  • 2020-08-31: other: GitHub reviewed and confirmed malicious activity

References