Junglewise Threat Intelligence

hdkye malicious package with cryptocurrency wallet theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The hdkye npm package is a malicious library designed to steal cryptocurrency wallets from infected systems. Any machine with this package installed should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate clean computer and complete system remediation.

Technical details

This npm package contains malware (CWE-506: Embedded Malicious Code) designed to locate and exfiltrate cryptocurrency wallets from the host system. All versions of hdkye are affected. The attack vector is network-based with no authentication or user interaction required—simply installing and running the package grants the attacker access to find and steal wallet credentials. Once installed, the package may provide full control of the system to external threat actors, making complete removal difficult and dangerous. Organizations should assume complete system compromise and conduct thorough incident response.

Affected products

  • npm hdkye all versions

Timeline

  • 2020-09-03: disclosed

References