Executive brief
js-sxa3 is a JavaScript npm package that was compromised with malicious code in version 0.8.0. The malicious code targeted Ethereum cryptocurrency wallets and performed unauthorized transactions to attacker-controlled addresses, potentially stealing user funds. Organizations using this package should immediately remove it and audit their cryptocurrency holdings for unauthorized activity.
Technical details
This is a supply-chain attack (CWE-506: Embedded Malicious Code) in which version 0.8.0 of the js-sxa3 npm package was intentionally poisoned with malicious code. The vulnerability requires no authentication or user interaction—any application that installed the affected version would automatically execute the malicious payload at runtime. The attack targets Ethereum users by performing unauthorized cryptocurrency transactions from victim wallets to attacker-controlled addresses, resulting in direct financial loss. Affected versions: 0.8.0 and any derivative versions should be removed immediately.
Affected products
- npm js-sxa3 0.8.0
Timeline
- 2020-09-03: disclosed