Executive brief
The rceat npm package contained malware designed to steal cryptocurrency wallets and private keys from infected computers. Any machine that installed this package should be considered completely compromised and all secrets, keys, and credentials should be immediately rotated from a secure system. The malicious code may have granted external attackers full system control, making simple uninstallation insufficient to remove all threats.
Technical details
This is a supply-chain attack delivered via a malicious npm package (CWE-506: Embedded Malicious Code). All versions of rceat contained malware explicitly designed to locate and exfiltrate cryptocurrency wallets and related secrets from the compromised system. The attack vector is installation/execution of the package via npm, requiring no authentication or special preconditions beyond the user running the package. An attacker achieves complete system compromise and exfiltration of sensitive cryptographic material. No patched version exists; the entire package is malicious and must be removed entirely, though full remediation may be impossible without system rebuild.
Affected products
- rceat all versions
Timeline
- 2020-09-03: disclosed