
A hacker under the pseudonym Right9CTRL gained access to the popular JavaScript library, infected it with malicious code and gained access to the bitcoin pickers of its users, ZDNET reports. According to the publication , the attacker could receive data from several million users.
JavaScript libraries contain a management code that application developers can use so as not to write the corresponding elements from scratch. Right9CTRL gained access to the Event-Stream library, which is used weekly up to two million people. According to Arstechnica , among users - both startups and large companies that are part of Fortune 500.
In August 2018, the creator of Event-Stream Dominic Tarr transferred the rights to the administrator to a person who proposed "help with its support."
“I don’t even know what to say,” he wrote on Github in November.
According to Tarra, when Right9ctrl wrote to him, he had not been engaged in the support of the library for some time and “didn’t receive anything from it”, so he agreed to transfer the rights to the person who expressed a desire to engage in the library.
The fact that the library was infected became known in early November 2018, but for some time it was not clear what exactly the malicious code was doing.
ZDNET with reference to “observation users” writes that, having gained access to Event-Stream, Right9ctrl wrote a new version of the library (3.3.6). The code added in it did not do anything until the user launched the Copay application - an electronic wallet developed by the bitcoin payment system Bitpay. Copay uses, among other things, the Event-Stream library.
When opening the wallet, the malicious code from the library was added to the Copay code, stole users, including secret keys, and sent to the server in Kuala Lumpur . Probably, using these data, Right9ctrl could withdraw cryptocurrency from the wallets of affected users.
Copay representatives recognized the vulnerability and called for users to urgently update the applications to the new version. The malicious version of Event-Stream 3.3.6 was also removed from the repository.
Whether the Right9CTRL hacker managed to steal cryptocurrency from the accounts of library users is unknown. According to Extremetech , it is almost impossible to calculate the attacker who managed to take bitcoins in this way, and it is impossible to insure the savings in cryptocurrency - unlike conventional monetary contributions.