JavaScript Code Compromises Bitcoin Wallets

A popular JavaScript library has been compromised by an unknown hacker who inserted malicious code to steal from cryptocurrency wallets.

The widely used open source software that has been compromised is event-stream, a code library with 2 million downloads.

According to Bleeping Computer event-stream is built to simplify working with Node.js streaming modules and it is available through the npmjs.com repository.

BitCoin © Mopic, Shutterstock 2013

Malicious code

Researchers found the malicious code last week, warned that earlier versions of the library includes a new component, ‘flatmap-stream’ version 0.1.1, that contains dangerous code.

This compromise was apparently introduced when Dominic Tarr, the original developer of Event-Stream, gave up the library and passed it to another developer, right9ctrl.

Unfortunately, it seems that Right9ctrl implemented the malicious changes as soon as they received access to the popular library. He or she then published the updated version.

“He [right9ctrl] emailed me and said he wanted to maintain the module, so I gave it to him. I don’t get anything from maintaining this module, and I don’t even use it anymore and haven’t for years,” Tarr reportedly said, adding that he no longer had publishing rights for the library on npmjs.com.

Dominic Tarr admitted he made a mistake by transferring the rights to the repository whilst it remained under his username.

It seems the malicious code targets libraries associated with the Copay Bitcoin wallet app, and it seems highly likely the intend was to steal wallet files.

Bleeping Computer said the injected code tries to steal the bitcoins in the wallet and then attempts to connect to copayapi.host and to the IP address 111.90.151.134 in Malaysia.

Right9ctrl later published an update without the malicious code embedded, in a move that some feel was designed to hide their tracks.

Do you know all about security? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Virgin Media O2 To Invest £700m To ‘Transform’ 4G, 5G Network

Virgin Media O2 confirms it will invest £2m a day for new mobile masts, small…

2 days ago

Tesla Cybertruck Deliveries On Hold Due To Faulty Side Trim

Deliveries of Telsa's 'bulletproof' Cybertruck are reportedly on hold, amid user complaints side trims are…

2 days ago

Apple Plots Live Translation Option For AirPods – Report

New feature reportedly being developed by Apple for iOS 19, that will allow AirPods to…

2 days ago

Binance Token Rises After Trump Stake Report

Binance BNB token rises after WSJ report the Trump family is in talks to secure…

3 days ago

iRobot Admits ‘Substantial Doubt’ Over Continued Operation

After failed Amazon deal, iRobot warns there is “substantial doubt about the Company's ability to…

3 days ago

Meta’s Community Notes To Use X’s Algorithm

Community Notes testing across Facebook, Instagram and Threads to begin next week in US, using…

3 days ago