Junglewise Threat Intelligence

js-she3 malicious package in npm

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

Version 0.8.0 of the js-she3 npm package contained malicious code designed to steal Ethereum cryptocurrency from users. When installed and used, the compromised version would siphon funds to unauthorized wallets, potentially resulting in direct financial loss to any developer or organization using this library.

Technical details

This is a supply-chain attack (CWE-506: Embedded Malicious Code) where the npm package js-she3 version 0.8.0 contained intentional malicious code targeting Ethereum transactions. The attack vector is network-based: developers who installed the package from npm and executed code depending on it would have the malicious logic run in their environment. The attacker achieves fund theft by hijacking Ethereum transactions and redirecting them to attacker-controlled wallets. The recommended fix is immediate removal of the package and verification that no cryptocurrency funds were compromised.

Affected products

  • npm js-she3 0.8.0

Timeline

  • 2020-09-03: disclosed

References