Junglewise Threat Intelligence

npm coinstirng malicious package with cryptocurrency wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The coinstirng npm package was a malicious package designed to steal cryptocurrency wallets from infected computers. Any system with this package installed should be considered fully compromised; all cryptographic keys and secrets must be rotated from a different, trusted machine, and complete removal cannot be guaranteed even after uninstallation.

Technical details

The vulnerability is a malicious package (CWE-506: Embedded Malicious Code) in which all versions of coinstirng contained malware designed to locate and exfiltrate cryptocurrency wallets from the host system. The attack vector is network-based (installation via npm) with no authentication or user interaction required beyond the initial installation. Once installed, the malware achieves arbitrary code execution with full system privileges, allowing attackers to harvest cryptographic keys and maintain persistent access to the compromised system. Remediation requires complete system rebuild or forensic verification that all malicious artifacts have been removed.

Affected products

  • npm coinstirng all versions

Timeline

  • 2020-09-03: disclosed: Vulnerability published in GitHub Advisory Database

References