Toutes les vulnérabilités
CRITICALSupply chainexploited in the wild

NPM-EVENT-STREAM-2018

npm · event-stream, flatmap-stream

Résumé

Disclosed November 20, 2018, the event-stream backdoor was a social-engineering takeover: a new 'volunteer' maintainer (GitHub user right9ctrl) gained control of the popular event-stream package and added a malicious dependency, flatmap-stream, in version 3.3.6. The backdoor existed only in the minified npm tarball, not in the GitHub source. It was surgically targeted at the Copay/BitPay bitcoin wallet, activating only in that build to harvest wallet private keys and seed when balances exceeded 100 BTC or 1000 BCH. Copay versions 5.0.2 through 5.1.0 shipped with the backdoor.

Références

Vulnérabilités liées

Tout Supply chain →