Junglewise Threat Intelligence

npm js-sia3 malicious code in version 0.8.0

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package js-sia3 was found to contain malicious code designed to steal cryptocurrency. Specifically, version 0.8.0 of this library targets Ethereum wallets and initiates unauthorized transactions to transfer funds to attacker-controlled accounts. Organizations using this package risk the immediate loss of digital assets and should remove the software from their environments immediately.

Technical details

The js-sia3 package (version 0.8.0) was identified as a malicious publication on the npm registry, classified under CWE-506 (Embedded Malicious Code). The package contains logic specifically designed to intercept or manipulate Ethereum cryptocurrency operations. When executed within an application, it performs unauthorized transactions, redirecting funds to wallets not owned by the user. This is a supply chain attack requiring no specific authentication or user interaction beyond the inclusion of the library in a project. The package has been flagged for removal, and users are advised to audit their environments for any unauthorized financial activity.

Affected products

  • npm js-sia3 0.8.0

Timeline

  • 2020-09-03: disclosed: Initial publication of the advisory

References