Executive brief
The npm package buffer-xkr version 2.0.2 contained malicious code designed to steal Ethereum cryptocurrency from users. The malware performed unauthorized transactions to wallets controlled by attackers, putting at risk any cryptocurrency holdings of users who installed this compromised version. Organizations using this package should immediately remove it and verify their Ethereum accounts for unauthorized activity.
Technical details
This vulnerability is classified as malicious code (CWE-506) intentionally injected into version 2.0.2 of the buffer-xkr npm package. The malware targeted Ethereum cryptocurrency, conducting unauthorized wallet transactions to addresses not controlled by the legitimate user. The attack requires only that a user install the malicious package version; no special preconditions or user interaction is needed beyond the initial installation. An attacker gains direct access to execute code in the user's environment and can drain cryptocurrency funds. The vulnerability has been addressed by removing the malicious package from the npm registry.
Affected products
- npm buffer-xkr 2.0.2
Timeline
- 2020-09-03: disclosed: Advisory published