Junglewise Threat Intelligence

js-shi3 malicious code execution in npm package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

js-shi3 is a JavaScript library published on npm that contained malicious code in version 0.8.0. The compromised package was designed to steal cryptocurrency by performing unauthorized Ethereum transactions from users' wallets to attacker-controlled accounts. Installation and execution of the malicious version could result in direct financial loss.

Technical details

The vulnerability is a supply-chain attack involving the injection of malicious code into the js-shi3 npm package. Version 0.8.0 contained code that interacted with Ethereum cryptocurrency wallets to execute unauthorized transactions. The attack requires no special preconditions—simply installing and running the compromised package version triggers the malicious behavior. An attacker can steal cryptocurrency funds directly. The recommended response is to remove the package from all environments and audit affected Ethereum accounts for unauthorized transactions.

Affected products

  • js-shi3 js-shi3 0.8.0

Timeline

  • 2020-09-03: disclosed

References