Executive brief
The npm package bpi39 is a malicious package designed to steal cryptocurrency wallets and other sensitive data from infected computers. All versions of this package contain malware with the ability to exfiltrate secrets and keys. Any system with this package installed should be considered fully compromised and requires immediate remediation including rotation of all credentials from a clean system.
Technical details
This is a malicious package attack (CWE-506: Embedded Malicious Code). All versions of bpi39 were intentionally designed with embedded malware to locate and exfiltrate cryptocurrency wallets from infected systems. The attack vector is network-based, requiring only that a developer or system install the package from the npm registry—no special authentication or user interaction beyond package installation is needed. Once installed, the malware gains full control of the infected computer, allowing attackers to steal cryptocurrency wallets, API keys, secrets, and other sensitive cryptographic material. Removal of the package does not guarantee removal of all malicious software, as the attacker may have established persistent backdoors during execution.
Affected products
- npm bpi39 all versions
Timeline
- 2020-09-04: disclosed