Bitcoin Siphoning Malware Infects Event-Stream

Bitcoin Siphoning Malware Infects Event-Stream

Malicious code was found in open-source Copay and BitPay. Now fixed, but stayed unnoticed for a while

Node.js is a widely used JavaScript backend framework for web applications. Node's functionality can be extended by adding various modules and libraries.

EventStream is one of the libraries that adds a lot of useful functions to Node.js. It has 2 million downloads and is used by Fortune 500 companies and many startups, with Copay and BitPay wallets being two of those companies.

EventStream is an open source code library and for a long time has been maintained by github user dominictarr.

At one point Dominic got tired and passed the publish rights to a random person who emailed him and asked him to give him the rights.

The person updated the library to include more modules that contained malware. The malware was designed to target cryptocurrency wallets that would include it into their production code. This backdoor would allow the person to siphon crypto out of user wallets.

The vulnerability went undetected for several weeks. Fortunately, no funds were stolen and the backdoor was eliminated.

For those interested in more details regarding the incident, you can access the comprehensive article entitled 'Widely used open source software contained bitcoin-stealing backdoor.'

Related news

Onegold by APMEX Now Accepts Bitcoin and Cryptocurrency Payments Powered by BitPay

Onegold is an online precious metals’ trading platform where investors go to buy precious metals such as gold and silver. Also, Onegold acts as an asset manager for investors to manage their possessions. The platform was founded by APMEX and Sprott for the aforementioned uses. The tradeable physical assets by Onegold are safely kept at the Canadian Royal Mint through which they are redeemed by APMEX in the case that a trade occurs or is executed. Very recently, the firm fully embraced Bitcoin and Bitcoin Cash as a form of payment by investors when purchasing the precious metals from Onegold. Each investor who bought gold and silver using Bitcoin and Bitcoin Cash was pre-disposed to a 4% discount of the total worth of goods sold. The exchange of precious metals with Bitcoin was made possible by relations with BitPay which is a leading experienced online platform that allows for Bitcoin and Bitcoin Cash Payments (have raised more than $70 million from investors) across vast borders and also comes in handy as a digital asset manager for their investors through BitPay online Wallet. The recent acceptance of cryptocurrency as a form of payment by Onegold was made easy/ possible because of an existing partnership between BitPay and APMEX that provided the base upon which the aforementioned was executed. Onegold CEO, Ken Lewis pointed out the reasons why they decided to take up Bitcoin as a form of payment was because use of credit cards had a couple of issues. Some of these issues included exposure to fraudulent activities which is a cost that would have to be incurred by Onegold after they have executed a sale but the payment becomes null. Also credit cards have a lot of costs and charges that would be incurred and be disadvantageous to the firm. On the other hand, Bitcoin and Bitcoin Cash come in handy because they are prone to all the aforementioned issues. Consequently use of cryptocurrency increases the plausible market for Onegold as they can transact with investors from the world over, and allows for openness and transparency of Onegold. BitPay works such that BitPay usually has a prepaid BitPay credit card that is powered by Metropolitan Commercial Bank which also allows turning of digital assets into dollars. Onegold believes that their turn into using digital backed metal gives them an upper edge as compared to their counterparts who use paper-backed assets.
Bitcoin Exchange Guide

Paxos teams up with BitPay

Paxos, the first regulated Trust company with blockchain expertise, has announced that Paxos Standard token (PAX) is now integrated with crypto payments processor BitPay as a settlement option for the processor’s merchants. With the PAX integration with BitPay, businesses and merchants the world ove... The post Paxos teams up with BitPay appeared first on CoinReport.

Bullion Giant APMEX Partners with BitPay to Let Investors Buy Gold with Bitcoin

Global crypto payment provider BitPay has announced the OneGold precious metals and digital gold marketplace is now accepting Bitcoin and Bitcoin Cash, according to a press release. OneGold — founded by APMEX, a leading precious metals retailer, and Sprott, an alternative asset manager — is focused on giving investors the ability to combine the “key The post Bullion Giant APMEX Partners with BitPay to Let Investors Buy Gold with Bitcoin appeared first on CCN

Hot news

By continuing to browse, you agree to the use of cookies. Read Privacy Policy to know more or withdraw your consent.