Junglewise Threat Intelligence

npm ruffer-xor malicious code in Ethereum transaction logic

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package ruffer-xor was found to contain malicious code designed to steal cryptocurrency. If installed, the package can intercept Ethereum transactions and redirect funds to unauthorized wallets. This poses a direct financial risk to any organization or individual using this library for blockchain-related operations.

Technical details

The ruffer-xor npm package (specifically version 2.0.2 and potentially others) contains a malicious payload classified as CWE-506 (Embedded Malicious Code). The code specifically targets Ethereum cryptocurrency operations, monitoring for transaction activity to redirect funds to attacker-controlled wallets. The attack is executed automatically upon the package's inclusion in a project, requiring no specific user interaction beyond the initial installation. Security researchers recommend immediate removal of the package and an audit of any Ethereum wallets associated with environments where the package was present.

Affected products

  • npm ruffer-xor All versions up to 2.0.2

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-03: disclosed: Advisory published

References