Junglewise Threat Intelligence

hooka-tools cryptomining trojan

Severity: info · Published 2020-09-01

Vendors: npm.

Executive brief

hooka-tools is a JavaScript library distributed via npm. Versions of this package were compromised and modified to secretly run a cryptocurrency miner in the background on systems where it is installed, consuming CPU resources and electricity without the user's knowledge or consent.

Technical details

The vulnerability is a supply-chain compromise in which the hooka-tools npm package was trojanized to include hidden cryptomining code. The malicious code runs silently in the background, leveraging the host system's CPU resources for unauthorized cryptocurrency mining. The attack vector is installation from the npm registry; no special authentication or user interaction is required beyond installing the package as a dependency. All affected versions have been unpublished from npm, though copies may persist in mirrors or caches. There is no patch; the recommendation is to remove the package entirely and switch to a safe alternative.

Affected products

  • hooka-tools hooka-tools 0.0.0 and later (all versions)

Timeline

  • 2020-09-01: disclosed

References