ThreatPaper
Unverified

The malicious event-stream code was downloaded 8 million times

Assessment

The figure counts downloads of event-stream over the roughly two and a half months the malicious dependency was present. It does not count downloads of the weaponised flatmap-stream@0.1.1, and it emphatically does not count installations where the payload did anything. The distinction is the whole design of the attack. The payload decrypted itself using npm_package_description — the description of the root package being built — as an AES-256 key. On any project other than Copay, whose description is "A Secure Bitcoin Wallet", decryption produced meaningless output and execution stopped. The population where the code executed is therefore Copay's build, and from there the shipped versions 5.0.2 to 5.1.0; the population where it stole anything is the subset of those users holding more than 100 BTC or 1,000 BCH. Three different numbers get reported as one: total package downloads in the millions, exposed wallet users in an unpublished but far smaller number, and targeted victims that BitPay never quantified. Rated Unverified rather than False because the download count itself is accurate — Snyk was describing reach, and its own post-mortem sets out the targeting mechanism precisely. What travels downstream is the number without the mechanism, which turns a measure of distribution into an implied measure of harm.

Where this claim appeared

Snyk · 2018-11-26

https://snyk.io/blog/malicious-code-found-in-npm-package-event-stream/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

event-stream: The npm Maintainer Handover That Backdoored a Bitcoin Wallet

Think this assessment is wrong? Report an error.