Executive brief
js-shq3 is a JavaScript library available through npm. Version 0.8.0 contained malicious code that secretly performed unauthorized cryptocurrency transactions, diverting Ethereum funds from users to attacker-controlled wallets. Organizations using this package may have suffered direct financial losses.
Technical details
This is a supply-chain attack involving intentional malicious code injection (CWE-506) in an npm package. The malicious version 0.8.0 of js-shq3 contained code that detected Ethereum cryptocurrency activity and redirected transactions to attacker-controlled wallets without user consent or knowledge. The vulnerability is triggered automatically upon package installation and execution, requiring no authentication or user interaction. An attacker gains the ability to steal cryptocurrency directly from affected users. Remediation is removal of the package and affected versions from all systems.
Affected products
- js-shq3 js-shq3 0.8.0
Timeline
- 2020-09-03: disclosed: Advisory published on GitHub and npm