Junglewise Threat Intelligence

js-wha3 malicious code in npm package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

js-wha3 is a JavaScript library published on npm. Version 0.8.0 contained intentionally malicious code designed to steal cryptocurrency by initiating unauthorized Ethereum transactions to attacker-controlled wallets. Users who installed this compromised version face direct financial loss.

Technical details

This vulnerability is a supply-chain attack involving deliberately injected malicious code (CWE-506: Embedded Malicious Code) in a published npm package. The malicious version 0.8.0 performs unauthorized cryptocurrency transactions, targeting Ethereum funds in user accounts. Attack vector is network-based through package installation; no special authentication or user interaction is required beyond downloading the compromised package. An attacker gains the ability to automatically transfer cryptocurrency from affected users' wallets. The recommended mitigation is immediate removal of the package and verification that no funds were transferred.

Affected products

  • js-wha3 js-wha3 0.8.0

Timeline

  • 2020-09-03: disclosed

References