Junglewise Threat Intelligence

npm buffe2-xor malicious code injection

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package buffe2-xor was found to contain malicious code designed to steal Ethereum cryptocurrency. When used in an application, the package can initiate unauthorized transactions to transfer funds to wallets controlled by the attacker. Organizations using this package should remove it immediately and audit their Ethereum accounts for suspicious activity.

Technical details

The npm package buffe2-xor, specifically version 2.0.2, contains a malicious payload classified as CWE-506 (Embedded Malicious Code). The package targets Ethereum cryptocurrency users by intercepting or initiating transactions to redirect funds to attacker-controlled wallets. The attack vector is remote and requires no authentication or user interaction beyond the inclusion of the library in a project. Security teams should treat any installation of this package as a total compromise of the environment's cryptocurrency assets and remove the dependency immediately.

Affected products

  • npm buffe2-xor 2.0.2

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-03: disclosed: Advisory published

References