Executive brief
The wbe3 npm package is malware designed to steal cryptocurrency wallets and other secrets from infected systems. Any computer with this package installed should be considered fully compromised, and all cryptographic credentials stored on that system should be rotated immediately from a secure alternative device. Complete removal is not guaranteed to eliminate all malicious code, as the attacker may have gained full system control.
Technical details
This npm package is intentionally malicious code (CWE-506) distributed via npm registry. All versions of wbe3 from 0.0.0 onward contain malware. The attack vector is network-based; installation occurs when a developer or automated tool pulls the package as a dependency without verification. The malware exfiltrates cryptocurrency wallet credentials and other sensitive data from the host system. No patch is available because the package itself is malicious; the only mitigation is removal and credential rotation from a separate, uncompromised system.
Affected products
- npm wbe3 all versions from 0.0.0 onwards
Timeline
- 2020-09-03: disclosed: Advisory published