Executive brief
The npm package "crpyto-js" was a malicious package designed to steal cryptocurrency wallets from compromised systems. Any computer with this package installed should be considered fully compromised, as the malware could provide attackers complete control over the system. All credentials, keys, and secrets stored on affected computers should be immediately rotated from a clean, unaffected machine.
Technical details
This is a supply-chain attack delivered via a typosquatting npm package (crpyto-js, a misspelling of crypto-js). All versions of the package contained malware that specifically targeted and exfiltrated cryptocurrency wallets and related secrets from infected systems. The attack vector is network-based (installation via npm package manager) with no authentication required and no user interaction beyond installing the package. The vulnerability allows arbitrary code execution during package installation, giving attackers complete system compromise and the ability to steal stored keys and wallet data.
Affected products
- npm crpyto-js all versions
Timeline
- 2020-09-03: disclosed