Junglewise Threat Intelligence

ripedm160 malicious package with cryptocurrency wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

ripedm160 is a malicious npm package designed to steal cryptocurrency wallets and private keys from infected systems. All versions of the package contained malware that could exfiltrate sensitive cryptographic material. Any system with this package installed should be considered fully compromised and all secrets must be rotated from a clean device.

Technical details

This is a malicious supply-chain attack (CWE-506: Embedded Malicious Code) in which the ripedm160 npm package was deliberately crafted to contain wallet-stealing malware. The attack vector is installation from the npm registry with no authentication required; the malware executes automatically upon package installation or import. The compromise is complete—the attacker gains the ability to exfiltrate cryptocurrency wallets, private keys, and other sensitive credentials stored on the system. No patch is available; removal is insufficient as full system compromise cannot be guaranteed.

Affected products

  • npm ripedm160 all versions

Timeline

  • 2020-09-03: disclosed

References