Junglewise Threat Intelligence

wallet-address-validtaor npm package malware

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

wallet-address-validtaor is a Node.js package distributed via npm that was found to contain malware designed to steal cryptocurrency wallets and secrets from infected systems. Any computer with this package installed should be considered fully compromised, as the malware grants attackers complete control and may have installed additional malicious software that persists beyond package removal.

Technical details

The wallet-address-validtaor npm package (all versions affected) contained intentionally malicious code (CWE-506: Embedded Malicious Code) designed to locate and exfiltrate cryptocurrency wallets and private keys from the host system. The attack vector is network-based via package installation on npm; no authentication or user interaction is required beyond installing the package. Once executed, the malware provides remote attackers with complete system access, enabling credential theft, persistent backdoor installation, and data exfiltration. No patch is available; complete system remediation from a clean device is the only recommended response.

Affected products

  • npm wallet-address-validtaor all versions

Timeline

  • 2020-09-03: disclosed

References