Junglewise Threat Intelligence

sb58 malicious package with wallet exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The sb58 npm package contained malware designed to steal cryptocurrency wallets and other sensitive data from infected systems. Any computer running this package should be considered fully compromised, with all cryptographic keys and secrets immediately rotated from a secure device. Complete removal and system recovery is necessary, as the malware may have established persistent access beyond the package itself.

Technical details

This is a malicious package (CWE-506: embedded malicious code) distributed via npm. All published versions of sb58 contained wallet-stealing malware that exfiltrated cryptocurrency credentials and sensitive keys from the host system. The attack requires no authentication or user interaction beyond initial package installation (network reachable via npm). The impact is total system compromise with data exfiltration of secrets; an attacker gains ability to steal cryptographic keys and potentially establish backdoor access. The advisory recommends complete system recovery; simply removing the package may not eliminate all malicious artifacts.

Affected products

  • npm sb58 all versions

Timeline

  • 2020-09-03: disclosed

References