Executive brief
The colne npm package contained malware designed to steal cryptocurrency wallets and other sensitive credentials from infected systems. Any computer with this package installed should be considered fully compromised, as the malicious code could provide attackers complete system control. All cryptographic keys, passwords, and secrets stored on affected machines must be rotated immediately from a different, uncompromised computer.
Technical details
This is a malicious package (CWE-506: Supply Chain Attack) where all versions of colne on npm contained embedded malware. The package was designed to discover and exfiltrate cryptocurrency wallets and sensitive credentials from the host system. The attack vector is network-based via package installation, with no authentication or user interaction required beyond installing the malicious dependency. An attacker gains full system access upon installation. No patch exists; the entire package must be removed and the system should be considered compromised.
Affected products
- npm colne all versions
Timeline
- 2020-09-03: disclosed