Junglewise Threat Intelligence

ripmed160 malicious package cryptocurrency wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The ripmed160 npm package contained malware designed to steal cryptocurrency wallets and related secrets from infected computers. Any system that installed this package should be considered fully compromised, as the malware grants outside entities broad control over the machine. All cryptographic keys, passwords, and sensitive credentials stored on affected systems must be rotated immediately from a secure, unaffected device.

Technical details

This vulnerability is a supply-chain attack in the form of a malicious npm package (CWE-506: Embedded Malicious Code). All versions of ripmed160 contained malware with the primary objective of discovering and exfiltrating cryptocurrency wallets and private keys from the host system. The attack vector is network-based; users downloading and installing the package from npm are compromised upon installation. No authentication or special preconditions are required—merely installing the package triggers the malicious payload. Once executed, the malware establishes persistent control, potentially allowing attackers to deploy additional malicious software. The package has been removed from npm; however, complete remediation requires full system inspection and rebuild, as the compromise is considered total.

Affected products

  • npm ripmed160 all versions

Timeline

  • 2020-09-03: disclosed

References