Junglewise Threat Intelligence

npm cxt malicious package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package "cxt" was distributed with built-in malware designed to steal cryptocurrency wallets and private keys from infected systems. Any system that installed or ran this package should be considered fully compromised, and all secrets and cryptographic credentials must be immediately rotated from a clean system, as the malware may have granted full control to external attackers.

Technical details

All versions of the cxt npm package contained embedded malware (CWE-506: Embedded Malicious Code). The malicious code was designed to discover and exfiltrate cryptocurrency wallet files and keys from the host system. The package would execute automatically upon installation or import. No patched version exists; the only remediation is complete removal of the package and comprehensive assessment for other backdoors, as removal alone may not eliminate all malicious code left by the initial compromise.

Affected products

  • npm cxt all versions

Timeline

  • 2020-09-03: disclosed
  • 2020-09-03: advisory: GitHub advisory published

References