Junglewise Threat Intelligence

js-qha3 malicious package with cryptocurrency theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

js-qha3 is a JavaScript library that was compromised to include malicious code designed to steal Ethereum cryptocurrency. Version 0.8.0 of the package performs unauthorized transactions, diverting funds to attacker-controlled wallets. Organizations using this package risk direct financial loss and cryptocurrency theft.

Technical details

This is a supply-chain attack (CWE-506: embedded malicious code) where a legitimate npm package was poisoned with code targeting Ethereum wallets. The malicious payload in version 0.8.0 executes automatically when the package is installed or imported, performing unauthorized blockchain transactions without user consent. The attack is network-based and requires no authentication or user interaction—anyone with the package installed is vulnerable. The attacker gains full control over Ethereum funds accessible from the affected system. Complete removal of the package and wallet auditing are the primary remediation steps.

Affected products

  • npm js-qha3 0.8.0

Timeline

  • 2020-09-03: disclosed

References