Junglewise Threat Intelligence

npm bitcoijns-lib malicious cryptocurrency wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

The npm package 'bitcoijns-lib' was found to be a malicious library designed to steal cryptocurrency wallets. This package mimics legitimate bitcoin libraries to trick developers into installing it. If used, it can exfiltrate private keys and digital assets, leading to a total loss of funds and a full compromise of the host system.

Technical details

The 'bitcoijns-lib' package is a malicious distribution (CWE-506) published to the npm registry. It contains code specifically designed to locate and exfiltrate cryptocurrency wallet files and associated secrets from the host environment. The attack vector is a supply chain compromise where the package is downloaded and executed during the build or runtime phase of an application. Because the package may grant full remote control to an attacker, any system where it was installed should be considered fully compromised, requiring a complete rotation of all credentials and potentially a full system wipe.

Affected products

  • npm bitcoijns-lib All versions

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-04: disclosed: Advisory published

References