Executive brief
The bwffer-xor npm package version 2.0.2 contained malicious code designed to steal Ethereum cryptocurrency. The malware intercepted cryptocurrency transactions and redirected funds to attacker-controlled wallets, putting users' digital assets at direct risk of theft.
Technical details
This is a malicious package attack (CWE-506: Embedded Malicious Code) in the bwffer-xor npm library. The malicious code was injected in version 2.0.2 and monitored Ethereum blockchain transactions initiated by applications using the package. When a transaction was detected, the malware altered the recipient wallet address to redirect funds to attacker-controlled addresses. The attack required the package to be installed and used in an Ethereum-related application; no user interaction or authentication bypass was needed beyond using the compromised library. Affected users should immediately remove the package and audit their Ethereum wallets for unauthorized transactions.
Affected products
- npm bwffer-xor 2.0.2
Timeline
- 2020-09-03: disclosed
- 2020-09-03: advisory: GitHub Advisory GHSA-7qg7-6g3g-8vxg published