Executive brief
The coinstirng npm package was a malicious package designed to steal cryptocurrency wallets from infected computers. Any system with this package installed should be considered fully compromised; all cryptographic keys and secrets must be rotated from a different, trusted machine, and complete removal cannot be guaranteed even after uninstallation.
Technical details
The vulnerability is a malicious package (CWE-506: Embedded Malicious Code) in which all versions of coinstirng contained malware designed to locate and exfiltrate cryptocurrency wallets from the host system. The attack vector is network-based (installation via npm) with no authentication or user interaction required beyond the initial installation. Once installed, the malware achieves arbitrary code execution with full system privileges, allowing attackers to harvest cryptographic keys and maintain persistent access to the compromised system. Remediation requires complete system rebuild or forensic verification that all malicious artifacts have been removed.
Affected products
- npm coinstirng all versions
Timeline
- 2020-09-03: disclosed: Vulnerability published in GitHub Advisory Database