Junglewise Threat Intelligence

crytpo-js malicious package distributing cryptocurrency wallet stealer

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The crytpo-js npm package contained malware designed to steal cryptocurrency wallets and private keys from infected systems. Any computer with this package installed should be considered fully compromised and all cryptographic secrets and keys rotated immediately from a different machine. Full system remediation may be required as the attacker may have gained persistent control.

Technical details

This is a supply-chain attack via a maliciously backdoored npm package (CWE-506: Embedded Malicious Code). All versions of crytpo-js (a typosquatted name mimicking the legitimate crypto-js library) contained code designed to locate and exfiltrate cryptocurrency wallets and private keys stored on the infected system. The attack vector is network-based: installation occurs when developers or CI/CD systems fetch the package from npm. No authentication bypass or privilege escalation is required; the malware executes with the privileges of the npm installation process. Once installed, the malware can achieve code execution and data exfiltration, compromising all secrets accessible to the affected user or service account.

Affected products

  • npm crytpo-js all versions

Timeline

  • 2020-09-03: disclosed
  • 2020-08-31: advisory: GitHub reviewed on this date

References