Junglewise Threat Intelligence

js-sxa3 malicious code in package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

js-sxa3 is a JavaScript npm package that was compromised with malicious code in version 0.8.0. The malicious code targeted Ethereum cryptocurrency wallets and performed unauthorized transactions to attacker-controlled addresses, potentially stealing user funds. Organizations using this package should immediately remove it and audit their cryptocurrency holdings for unauthorized activity.

Technical details

This is a supply-chain attack (CWE-506: Embedded Malicious Code) in which version 0.8.0 of the js-sxa3 npm package was intentionally poisoned with malicious code. The vulnerability requires no authentication or user interaction—any application that installed the affected version would automatically execute the malicious payload at runtime. The attack targets Ethereum users by performing unauthorized cryptocurrency transactions from victim wallets to attacker-controlled addresses, resulting in direct financial loss. Affected versions: 0.8.0 and any derivative versions should be removed immediately.

Affected products

  • npm js-sxa3 0.8.0

Timeline

  • 2020-09-03: disclosed

References