Junglewise Threat Intelligence

bwffer-xor malicious package with Ethereum wallet theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The bwffer-xor npm package version 2.0.2 contained malicious code designed to steal Ethereum cryptocurrency. The malware intercepted cryptocurrency transactions and redirected funds to attacker-controlled wallets, putting users' digital assets at direct risk of theft.

Technical details

This is a malicious package attack (CWE-506: Embedded Malicious Code) in the bwffer-xor npm library. The malicious code was injected in version 2.0.2 and monitored Ethereum blockchain transactions initiated by applications using the package. When a transaction was detected, the malware altered the recipient wallet address to redirect funds to attacker-controlled addresses. The attack required the package to be installed and used in an Ethereum-related application; no user interaction or authentication bypass was needed beyond using the compromised library. Affected users should immediately remove the package and audit their Ethereum wallets for unauthorized transactions.

Affected products

  • npm bwffer-xor 2.0.2

Timeline

  • 2020-09-03: disclosed
  • 2020-09-03: advisory: GitHub Advisory GHSA-7qg7-6g3g-8vxg published

References