Junglewise Threat Intelligence

CVE-2019-19771: lodahs npm package malware

CVE-2019-19771 · Severity: low · CVSS 3.1 · Published 2019-12-16

Vendors: npm.

Executive brief

lodahs is a malicious npm package designed to steal cryptocurrency wallets and exfiltrate cryptographic keys from infected systems. Any computer with this package installed should be considered fully compromised, as the malware may have granted outside entities full control of the system. Complete key rotation from a clean machine and full system remediation are required.

Technical details

This npm package contains malware (CWE-506: Embedded Malicious Code) present in all versions from 0.0.1 onward. The malware targets cryptocurrency wallets and exfiltrates sensitive key material from the host system. The attack vector is installation via npm package manager; compromise occurs upon package installation and execution. An attacker gains the ability to extract cryptocurrency wallets and cryptographic secrets, potentially granting persistent access to the compromised system. No patched version exists; the package itself is malicious and must be completely removed and replaced.

Affected products

  • npm lodahs 0.0.1 and later

Timeline

  • 2019-12-16: disclosed
  • 2019-12-12: other: NVD publication

References