Executive brief
The npm package 'bs58chek' has been identified as a malicious library designed to steal cryptocurrency wallets. This package mimics legitimate software but contains hidden code that exfiltrates sensitive financial keys and secrets to an external server. Any system where this package was installed should be considered fully compromised, potentially leading to the total loss of digital assets and unauthorized access to corporate secrets.
Technical details
All versions of the npm package 'bs58chek' contain malware classified under CWE-506 (Embedded Malicious Code). The package was specifically engineered to scan the host environment for cryptocurrency wallet files and exfiltrate them to a remote attacker-controlled server. The attack vector is remote and requires no authentication or user interaction beyond the installation of the package. Because the malware may establish persistent access or install additional backdoors, simple removal of the package is insufficient; a full system audit and rotation of all stored credentials from a clean machine are required.
Affected products
- npm bs58chek All versions
Timeline
- 2020-08-31: advisory: GitHub reviewed the advisory
- 2020-09-04: disclosed: Advisory published