Junglewise Threat Intelligence

npm hdeky malicious code injection

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package 'hdeky' has been identified as a malicious library designed to steal cryptocurrency wallets from infected systems. If this package is installed, it can exfiltrate sensitive financial keys and potentially give attackers full control over the affected computer. Organizations should consider any system with this package installed to be fully compromised and rotate all stored credentials immediately.

Technical details

The 'hdeky' npm package is a malicious library (CWE-506) that contains malware across all published versions. The primary payload is designed to scan the host filesystem for cryptocurrency wallet files and exfiltrate them to a remote server controlled by the attacker. Because the package executes during installation or runtime, it can achieve full system compromise. Security professionals should assume that any environment where this package was present has been breached, necessitating a full system wipe and the rotation of all secrets, API keys, and credentials stored on the machine.

Affected products

  • npm hdeky All versions

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-03: disclosed: Advisory published

References