Junglewise Threat Intelligence

cuffer-xor malicious package with cryptocurrency theft payload

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

cuffer-xor is a JavaScript library published to npm. Version 2.0.2 was found to contain malicious code that steals Ethereum cryptocurrency by initiating unauthorized transactions from affected users' wallets. Any application or developer that installed this compromised version is at immediate risk of financial loss.

Technical details

This is a supply-chain attack involving intentional malicious code injection (CWE-506). Version 2.0.2 of the cuffer-xor npm package was found to contain code that targets Ethereum wallets and executes unauthorized cryptocurrency transactions to attacker-controlled addresses. The attack requires no special preconditions beyond installation of the affected version; the malicious payload executes during normal package usage. Any developer or application using this library version is at risk of wallet compromise and financial theft. The vulnerability has been addressed by removal of the malicious package version from the ecosystem.

Affected products

  • npm cuffer-xor 2.0.2

Timeline

  • 2020-09-03: disclosed: Malicious package version 2.0.2 disclosed in advisory GHSA-6xm4-p6r2-mwrc
  • 2020-08-31: other: GitHub security team reviewed and confirmed malicious code

References