All vulnerabilities
CRITICALSupply chainexploited in the wild

NPM-EVENT-STREAM-2018

npm · event-stream, flatmap-stream

Summary

Disclosed November 20, 2018, the event-stream backdoor was a social-engineering takeover: a new 'volunteer' maintainer (GitHub user right9ctrl) gained control of the popular event-stream package and added a malicious dependency, flatmap-stream, in version 3.3.6. The backdoor existed only in the minified npm tarball, not in the GitHub source. It was surgically targeted at the Copay/BitPay bitcoin wallet, activating only in that build to harvest wallet private keys and seed when balances exceeded 100 BTC or 1000 BCH. Copay versions 5.0.2 through 5.1.0 shipped with the backdoor.

References

Related vulnerabilities

All Supply chain →