Junglewise Threat Intelligence

npm bpi39 malicious package

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

The npm package bpi39 is a malicious package designed to steal cryptocurrency wallets and other sensitive data from infected computers. All versions of this package contain malware with the ability to exfiltrate secrets and keys. Any system with this package installed should be considered fully compromised and requires immediate remediation including rotation of all credentials from a clean system.

Technical details

This is a malicious package attack (CWE-506: Embedded Malicious Code). All versions of bpi39 were intentionally designed with embedded malware to locate and exfiltrate cryptocurrency wallets from infected systems. The attack vector is network-based, requiring only that a developer or system install the package from the npm registry—no special authentication or user interaction beyond package installation is needed. Once installed, the malware gains full control of the infected computer, allowing attackers to steal cryptocurrency wallets, API keys, secrets, and other sensitive cryptographic material. Removal of the package does not guarantee removal of all malicious software, as the attacker may have established persistent backdoors during execution.

Affected products

  • npm bpi39 all versions

Timeline

  • 2020-09-04: disclosed

References