Executive brief
The commanedr npm package contained malware designed to steal cryptocurrency wallets from infected computers. Any system with this package installed should be considered fully compromised; attackers gained access to search for and extract wallet credentials and other sensitive cryptocurrency assets. All credentials, keys, and secrets on affected machines must be rotated immediately from a clean device, and the package should be removed, though full remediation cannot be guaranteed due to the level of system access granted to attackers.
Technical details
This is a malicious software package (CWE-506: Embedded Malicious Code) affecting all versions of the commanedr npm library. The package was intentionally designed to locate and exfiltrate cryptocurrency wallets from the host system. The attack vector is installation and execution of the package via npm; no authentication, network access, or user interaction beyond package installation is required for compromise. Once installed, the malware provides attackers with full control over the affected system, enabling theft of stored wallet files, credentials, and other sensitive data. No patch is available; the only remediation is complete removal and system recovery, though persistence mechanisms may remain.
Affected products
- npm commanedr all versions
Timeline
- 2020-09-03: disclosed: Vulnerability published to OSV database