Junglewise Threat Intelligence

degbu malicious package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The degbu npm package is malicious software designed to steal cryptocurrency wallets from infected computers. Any system that installed or ran this package should be considered fully compromised, and all secrets and keys must be immediately rotated from a secure, unaffected computer. Even after removal, there is no guarantee that the malware has been fully eliminated from the system.

Technical details

This is a malicious package (CWE-506) distributed via npm that executes payload code designed to locate and exfiltrate cryptocurrency wallets. All versions from 0.0.0 onwards are affected. The attack vector is network-based with no authentication or user interaction required beyond initial package installation. Once installed, the malware gains arbitrary code execution on the host system, allowing an attacker to search for and steal sensitive wallet files and keys. No patch is available because the package is malware and should be completely removed from all systems.

Affected products

  • npm degbu all versions

Timeline

  • 2020-09-03: disclosed: Malicious package disclosed via GitHub advisory

References