Junglewise Threat Intelligence

npm buffer-xov malicious code targeting Ethereum wallets

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package buffer-xov was found to contain malicious code designed to steal cryptocurrency. This library, which may have been mistakenly installed by developers, targets Ethereum wallets and initiates unauthorized transactions to external accounts. Organizations using this package face immediate financial risk and should audit their environments for unauthorized fund transfers.

Technical details

The npm package buffer-xov (specifically version 2.0.2 and potentially others) contains a malicious payload classified as CWE-506 (Embedded Malicious Code). The package is designed to intercept or manipulate Ethereum cryptocurrency operations, redirecting funds to attacker-controlled wallets. The attack vector is remote and requires no authentication or specific user interaction beyond the inclusion of the library in a project. Security researchers recommend immediate removal of the package and a full audit of any Ethereum accounts associated with the environment where the package was deployed.

Affected products

  • npm buffer-xov All versions up to 2.0.2

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-03: disclosed: Advisory published

References