Wallets of world cryptocurrencies in danger after attack on JavaScript

Foto del autor

By Berto R

An attack on the software supply chain would be in process, shaking the cryptocurrency ecosystem through JavaScript. According to a group of computer vulnerabilities researchers who write under the name of JDSTAERK, countless NPM development packages (nodes packages) received malicious updates.

Researchers would have discovered that the account of a developer known as «Qix» was violated, allowing The malicious code distribution in tools that accumulate more than 47 million downloads Weekly. Although it falls mainly on JavaScript developers throughout the Internet, the attack could indirectly affect end users to compromising cryptocurrency wallets.

The incident would have originated in the NPM repository, a platform that houses open source packages essential for the development of JavaScript applications.

These packages, used by thousands of projects worldwide, are common dependencies on servers and web applications. The committed account would have allowed attackers Publish altered versions of popular packagesintroducing a malicious code designed to steal stealthily when stealing cryptocurrency funds.

According to the analysis published in the jdstaerk.substack.com blog, the malware is specifically activated when it detects the presence of a cryptocurrency wallet as Metamask.

The malicious code operates in two phases. If you do not find a purse, run a passive attack, trying to send data to an external server. However, the real danger arises when it detects an active Wallet. In this scenario, malware intercepts communications between the wallet and the user, manipulating real -time transactions from the clipboard of the operating system.

Researchers describe in more detail the fraudulent process:

When the user starts a transaction (for example, eth_sendTransaction), Malware intercepts the data before sending them to the Wallet for its signature. Then modify the transaction in the memory, replacing the direction of the legitimate recipient with the direction of an attacker. The manipulated transaction is forwarded to the user’s purse for approval. If the user does not meticulously verify the address on the confirmation screen, he will sign a transaction that sends their funds directly to the attacker.

JDstaerk, group of investigators.

Although end users are not the direct objective, the omnipresence of these packages in software projects amplifies the risk, which is not directly mentioned in the JDSTAERK analysis.

Charles Guillemet, Cto de Ledger and who echoed the news, warns that Only users who use wallet hardware and can execute a visible and safe signature process are safe in front of the software supply chain attack.

Deja un comentario