Executive brief
The npm package 'bufger-xor' has been identified as containing malicious code designed to steal cryptocurrency. If installed, the package can intercept Ethereum transactions and redirect funds to unauthorized wallets. This poses a direct financial risk to any organization or individual using this library in their development environment or applications.
Technical details
The npm package 'bufger-xor' (specifically version 2.0.2 and potentially others) contains a backdoor classified as CWE-506 (Embedded Malicious Code). The package is designed to target Ethereum cryptocurrency operations, performing unauthorized transactions to wallets controlled by the attacker. The attack vector is remote and requires no authentication or user interaction beyond the installation and execution of the library within an application. Users are advised to remove the package immediately and audit their Ethereum wallets for unauthorized activity.
Affected products
- npm bufger-xor All versions up to 2.0.2
Timeline
- 2020-08-31: advisory: GitHub reviewed the advisory
- 2020-09-03: disclosed: Advisory published