Junglewise Threat Intelligence

js-rha3 malicious package in cryptocurrency transaction handler

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

js-rha3 is a JavaScript library used for cryptographic operations. Version 0.8.0 contained intentionally malicious code designed to steal Ethereum funds by redirecting cryptocurrency transactions to attacker-controlled wallets without the user's knowledge or consent. Organizations using this library version risk unauthorized loss of cryptocurrency assets.

Technical details

This is a malicious package vulnerability (CWE-506: Embedded Malicious Code) where version 0.8.0 of the js-rha3 npm library contained intentionally embedded malicious code. The vulnerability is exploited at runtime without authentication or user interaction required when the affected version is installed and used in an application. The malicious code intercepts Ethereum cryptocurrency transactions and redirects funds to wallets controlled by the attacker. The vulnerability was discovered and disclosed via GitHub advisories in September 2020; remediation involves immediate removal of the affected package version from all environments and verification that no cryptocurrency assets were compromised.

Affected products

  • npm js-rha3 0.8.0

Timeline

  • 2020-09-03: disclosed: Vulnerability disclosed in GitHub advisories

References