Junglewise Threat Intelligence

juffer-xor malicious package targeting Ethereum wallets

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

juffer-xor is an npm package library. Version 2.0.2 contained malicious code designed to steal cryptocurrency by initiating unauthorized Ethereum transactions from users' wallets to attacker-controlled accounts. Users who installed this version risk direct financial loss if they have Ethereum funds in connected wallets.

Technical details

This vulnerability is classified as malicious code injection (CWE-506). Version 2.0.2 of the juffer-xor npm package was deliberately backdoored with code that executes upon installation or runtime. The malicious payload intercepts Ethereum wallet operations and initiates unauthorized cryptocurrency transactions to wallets under attacker control. No authentication or user interaction is required beyond installing the compromised package version. Any application or user running code from juffer-xor v2.0.2 with access to Ethereum wallet credentials or private keys is at risk of financial theft. The vulnerability requires immediate removal of the affected package version from all environments.

Affected products

  • juffer-xor 2.0.2

Timeline

  • 2020-09-03: disclosed

References