Executive brief
The npm package 'buffes-xor' was found to contain malicious code designed to steal cryptocurrency. If installed, the package can automatically redirect Ethereum transactions to wallets controlled by the attacker. This poses a direct financial risk to any organization or individual using this library in their blockchain-related applications.
Technical details
The 'buffes-xor' package (specifically version 2.0.2 and potentially others) contains a malicious payload classified as CWE-506 (Embedded Malicious Code). The code is designed to intercept or initiate Ethereum transactions, sending funds to attacker-controlled wallet addresses. The attack vector is remote and requires no authentication or specific user interaction beyond the initial installation of the compromised package. Users are advised to immediately remove the package and audit any Ethereum wallets that may have been accessed by environments where this code was running.
Affected products
- npm buffes-xor All versions up to 2.0.2
Timeline
- 2020-08-31: advisory: GitHub reviewed the advisory
- 2020-09-03: disclosed: Advisory published