Junglewise Threat Intelligence

ks-sha3 malicious package with cryptocurrency theft

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The ks-sha3 JavaScript library, commonly used for cryptographic operations, contained malicious code in version 0.8.0 that targeted Ethereum cryptocurrency wallets. The malicious payload would perform unauthorized transactions, draining cryptocurrency from affected users' wallets to accounts controlled by the attacker. Organizations using this package may have suffered direct financial loss and should immediately remove it and audit their Ethereum accounts for unauthorized activity.

Technical details

The ks-sha3 npm package version 0.8.0 contained intentionally injected malicious code (CWE-506: Embedded Malicious Code). The malicious payload specifically targeted users with Ethereum cryptocurrency and performed unauthorized transactions to wallets outside the user's control, resulting in direct financial theft. As a supply chain compromise, the attack required no user interaction or authentication bypass—users who installed the compromised version automatically executed the malicious code upon package installation and use. The attacker gained full control over cryptocurrency transactions, enabling complete financial compromise. Users must immediately remove version 0.8.0 and audit their Ethereum wallets for unauthorized activity. There is no patch for this version; use only versions other than 0.8.0.

Affected products

  • npm ks-sha3 0.8.0

Timeline

  • 2020-09-03: disclosed

References