Bitcoin Forum
May 05, 2024, 10:22:55 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Hacker Backdoors JavaScript Library to Steal Bitcoin Funds  (Read 204 times)
CryptopieceOfficial (OP)
Jr. Member
*
Offline Offline

Activity: 57
Merit: 2


View Profile
November 26, 2018, 11:23:18 PM
 #1

A hacker has gained (legitimate) access to a popular JavaScript library and has injected malicious code that steals Bitcoin and Bitcoin Cash funds stored inside BitPay's Copay wallet apps. The presence of this malicious code was identified last week, but until Nov 26, have researchers been able to understand what the heavily obfuscated malicious code actually does.
1714947775
Hero Member
*
Offline Offline

Posts: 1714947775

View Profile Personal Message (Offline)

Ignore
1714947775
Reply with quote  #2

1714947775
Report to moderator
"Governments are good at cutting off the heads of a centrally controlled networks like Napster, but pure P2P networks like Gnutella and Tor seem to be holding their own." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714947775
Hero Member
*
Offline Offline

Posts: 1714947775

View Profile Personal Message (Offline)

Ignore
1714947775
Reply with quote  #2

1714947775
Report to moderator
1714947775
Hero Member
*
Offline Offline

Posts: 1714947775

View Profile Personal Message (Offline)

Ignore
1714947775
Reply with quote  #2

1714947775
Report to moderator
1714947775
Hero Member
*
Offline Offline

Posts: 1714947775

View Profile Personal Message (Offline)

Ignore
1714947775
Reply with quote  #2

1714947775
Report to moderator
gesdan
Full Member
***
Offline Offline

Activity: 616
Merit: 100



View Profile
November 26, 2018, 11:55:04 PM
 #2

hmm. javascript is the language that can be bundled with the script. maybe it possible that the hacker gets all the information about the wallet using the javascript. and i think we should careful with our wallet because of this news

pooya87
Legendary
*
Offline Offline

Activity: 3444
Merit: 10549



View Profile
November 27, 2018, 03:25:29 AM
 #3

for anyone interested here is the link: https://www.theregister.co.uk/2018/11/26/npm_repo_bitcoin_stealer/

and you should know that it is not just affecting BitPay wallets, it is affecting any other program that is using this rather popular library. so if your wallet is written in JavaScript then you may want to stop using it until you confirm it was not using that library.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
btc_angela
Hero Member
*****
Offline Offline

Activity: 2604
Merit: 542



View Profile
November 27, 2018, 03:38:59 AM
 #4

A hacker has gained (legitimate) access to a popular JavaScript library and has injected malicious code that steals Bitcoin and Bitcoin Cash funds stored inside BitPay's Copay wallet apps. The presence of this malicious code was identified last week, but until Nov 26, have researchers been able to understand what the heavily obfuscated malicious code actually does.

Is this one factor that contributed to the current dip? I have yet to look at this news but its really scary if you're using a wallet written in JavaScript and secretly stealing your bitcoin. Those criminals are really one step ahead of us, so just be careful with your crypto wallet.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Kakmakr
Legendary
*
Offline Offline

Activity: 3444
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
November 27, 2018, 06:24:44 AM
 #5

This was a sneaky one.  Roll Eyes

Someone got publishing rights to the event-stream library on GitHub that are used by BitPay and they injected some malware or malicious code.

BitPay does not develop the libraries on their own and blindly trust these Open source libraries. This is why these centralized services are targeted, because they are simply too lazy and stingy to pay reputable developers to develop safe and secure sites for them.  Angry

Hackers knows this and they target code like this that are used by more than one "target"  Roll Eyes

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
btyco
Copper Member
Jr. Member
*
Offline Offline

Activity: 364
Merit: 4


View Profile
November 27, 2018, 07:34:18 AM
 #6

People think open source is secure because someone has vetted the code, however it is rare that anyone actually does and just focuses on what it does and if it can be used

DarkPayCoin - [100% community governed and built]
[-] Website  [-] ANN Thread  [-] Discord  [-] Twitter  [-] Telegram
\ HIGH ROI, Low supply / - \ A privacy focused MN/PoS coin /
Pursuer
Legendary
*
Offline Offline

Activity: 1638
Merit: 1163


Where is my ring of blades...


View Profile
November 27, 2018, 08:19:41 AM
 #7

this is yet another reminder of the importance of cold storage. if you have your coins in cold storage like a paper wallet, bugs like this would never affect you and your coins will remain safe. the hot wallets should always only contain the amount that you want to spend.

Only Bitcoin
bitfocus
Member
**
Offline Offline

Activity: 532
Merit: 15


View Profile
November 27, 2018, 11:42:12 AM
 #8

a very sneaky one, no doubt! common users has very little defense against malwares that uses JavaScript as it can be easily embedded in any web-page!
metalglowd
Member
**
Offline Offline

Activity: 546
Merit: 10

💲 EMIREX EXCHANGE 💲


View Profile WWW
November 27, 2018, 11:44:43 AM
 #9

A hacker has gained (legitimate) access to a popular JavaScript library and has injected malicious code that steals Bitcoin and Bitcoin Cash funds stored inside BitPay's Copay wallet apps. The presence of this malicious code was identified last week, but until Nov 26, have researchers been able to understand what the heavily obfuscated malicious code actually does.

it seems that this is one of the factors of the crypto failure that still exists, and more news days about hacking wallet and exchange are increasing. Previously I also heard about the weaknesses in API trading in one of the markets, this made the price of the major coin in the market a severe dump, but fortunately the hackers could not cash out.

                             ❱  Whitepaper  ❱   E M R X ─ Token ─   :   LEARN MORE   
      E M I R E X         ─── إمركس ───          :         The Infrastructure for the
[ ◾ telegram   ◾ facebook   ◾ TWITTER ]   New Digital Economy
Anarchist
Sr. Member
****
Offline Offline

Activity: 531
Merit: 258


View Profile
November 27, 2018, 06:25:28 PM
 #10

It isn't only inside BitPay's Copay wallet apps but all crypto wallets, in general, that use Javascript. Don't worry Copay isn't the only one and you can expect to hear more about it and people with lost funds, in a few days.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!