Junglewise Threat Intelligence

wallet-address-vaildator malware in npm package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The wallet-address-vaildator npm package, which is used by developers to validate cryptocurrency wallet addresses, contained malware designed to steal cryptocurrency wallets and private keys. Any computer with this package installed should be considered fully compromised, as the attacker gained complete control and may have installed additional malicious software beyond just this package.

Technical details

This is a malicious package (CWE-506) that was intentionally designed to exfiltrate cryptocurrency wallets and secrets. All versions of the package contained the malware from initial release. The attack vector is local/supply-chain: developers install the package via npm and execute it as part of their build or application runtime. Once installed, the malware can steal cryptographic keys, private keys, and wallet credentials stored on the compromised system. Full system compromise should be assumed; removal of the package alone may not eliminate all introduced malware.

Affected products

  • npm wallet-address-vaildator all versions (0.0.0+)

Timeline

  • 2020-09-03: disclosed

References