Breach 025 / 076

Copay Cryptocurrency Wallet Data Breach

In November 2018, the Copay cryptocurrency wallet, developed by BitPay, suffered a data breach due to a malicious version of the event-stream Node.js library. The breach involved unauthorized access to users’ private keys and cryptocurrency assets through dependency injection of malicious code by threat actors, significantly affecting wallets with considerable holdings. The attack highlighted vulnerabilities in third-party dependencies within the open-source software ecosystem.
Sector
Financial Services
Year

Executive Summary

In November 2018, the Copay cryptocurrency wallet, developed by BitPay, experienced a data breach due to a malicious update to the event-stream Node.js library, specifically within its flatmap-stream dependency. Unauthorized access to users’ private keys and cryptocurrency funds was achieved, significantly impacting wallets containing over 100 Bitcoins or 1000 Bitcoin Cash source .

Key Dates

  • August 5, 2018: Initial release of the flatmap-stream package.
  • September 9, 2018: Integration of flatmap-stream into event-stream.
  • October 5, 2018: Introduction of malicious code into flatmap-stream.
  • November 27, 2018: Public disclosure following detection and action by npm’s security team source .

Severity of Impact

The breach severely affected users of Copay wallet versions 5.0.2 through 5.1.0, resulting in potential theft and exposure of cryptocurrency assets. This revealed significant vulnerabilities in dependencies used by millions of applications source .

Threat Actors

The main threat actor involved was reportedly a GitHub user named right9ctrl, who used social engineering tactics to gain the ability to inject malicious code into a trusted package within the Node.js ecosystem source .

Estimated Number of Affected Entities

Although precise numbers aren’t available, the library was downloaded millions of times, indicating substantial potential exposure for users reliant on the event-stream library source .

Consequences

Direct Consequences

  • Theft and loss of cryptocurrencies due to unauthorized private key access source .

Collateral Consequences

  • Erosion of trust in the security of Node.js libraries and open-source software dependencies, highlighting systemic vulnerabilities source .

Novel Elements

The attack leveraged dependency manipulation within an open-source library ecosystem, pointing out a systemic risk in managing software supply chains. This calls for comprehensive strategies to enhance security policies around third-party modules source .

Initial Organizational Response

Copay promptly issued an advisory for users to discontinue using the compromised versions and released a secure update (version 5.2.0). Users are urged to enhance audit and validation of third-party dependencies source .

Current Status

The malicious package has been removed from the npm repository. Comprehensive audits and improvements in dependency management practices are recommended to counter future threats source .

Incident Overview

Breach Timeline and Details

Background

The November 2018 breach of the Copay cryptocurrency wallet, a product by BitPay, was executed through a malicious npm package dependency. This involved the event-stream library wherein an unknown entity embedded malicious code, enabling the theft of users’ private keys and cryptocurrency funds.

Chronological Sequence of Events

  • August 5, 2018: flatmap-stream was initially published on npm by a user named Antonio Macias.
  • September 4, 2018: User right9ctrl committed various minor upgrades and enhancements to the event-stream repository.
  • September 9, 2018: Incorporation of flatmap-stream into event-stream, creating version 3.3.6 with this dependency.
  • October 5, 2018: Malicious version 0.1.1 of flatmap-stream released, introducing harmful code.
  • November 19, 2018: Report of unrecognized deprecation warnings in event-stream by NewEraCracker, initiating suspicion.
  • November 20, 2018: Security concerns emphasized by FallingSnow, speculating a potential code injection attack.
  • November 26, 2018: npm removed the malicious flatmap-stream package and [email protected] following reports. Control of the package transitioned to npm to mitigate future issues.
  • November 27, 2018: Publicly disclosed breach, identifying the malware’s focus on Copay.

Technical Details of the Exploit

The breach exploited supply chain vulnerabilities within the open-source Node.js application ecosystem.

  • Mechanism: The compromised version of flatmap-stream within event-stream allowed attackers to extract sensitive user information, specifically targeting Copay wallets with over 100 Bitcoin or 1000 Bitcoin Cash.
  • Obfuscation Techniques: Malicious code was effectively obscured within legitimate updates, delaying immediate detection.

Systems Affected and Impact

Directly Impacted

Copay versions 5.0.2 to 5.1.0 employed the malicious event-stream dependency, leading to financial implications from unauthorized cryptocurrency access.

Broader Implications

The event highlighted the geostrategic risks in dependency management within decentralized software systems, necessitating heightened vigilance and vetting of third-party setups.

Technical Root Cause Analysis

Technical Vulnerabilities and Exploitation

Malicious Dependency Injection

The breach’s root cause was the compromise of event-stream, version 3.3.6, incorporating a malicious dependency flatmap-stream. This occurred after a social engineering attack where right9ctrl transferred maintainer rights.

  • Social Engineering Transition: right9ctrl leveraged assumed trust to insert malicious payload by assuming administrative rights source .

Exploitative Flaws

Exploiting Trust Models

The open-source ecosystem’s inherent reliance on trust enabled this exploitation during maintainer transitions without sufficient review source .

Dependency Scrutiny Shortfall

The application of event-stream without reevaluating imports allowed complete integration of malicious components.

Detailed Exploitation Process

  1. Decryption and Payload Activation: The flatmap-stream was configured to activate only under Copay-specific conditions, using npm_package_description to decrypt malicious payloads via AES.
  2. Build-Time Activation: Copay versions between 5.0.2 and 5.1.0 executed scripts extracting private keys, checking wallet balances and targeting specific thresholds, leading to unauthorized access source .
  3. Data Exfiltration: Compromised data, including private keys, was transmitted to a server managed by the attacker at IP address 111.90.151.134 source .

Failed Security Controls

Shortcomings in Dependency Management

  • Lack of Automated Scanning Abilities: Absence of effective automation for alerting malicious dependency integrations allowed undetected entry of flatmap-stream into the ecosystem.

Security Oversights and Consequences

  • Package Administration Transfer Lapse: Administrator control transfer without intense scrutiny permitted malicious code introduction.
  • Cryptographic Exploitation: Misuse of the npm_package_description variable for decryption demonstrated critical security lapses.

Network Infrastructure Vulnerabilities

  • Central Repository Risks: Dependence on npm as a central repository pointed out vulnerabilities to harmful code propagation without immediate detection source .

Adherence to Industry Standards and Practices

The incident showcases failures in adhering to key industry standards for managing third-party dependencies and verifying open-source code integrity.

Attack Vector and Methodology

Initial Intrusion

The Copay cryptocurrency wallet breach of November 2018 was initiated through a popular Node.js library, event-stream. An entity known as right9ctrl requested maintainer rights from Dominic Tarr, the previous maintainer of the library, exploiting his inactivity. This social engineering maneuver enabled repository control transfer and subsequent malicious code introduction source .

Subsequent Strategies and Techniques

After access acquisition, obfuscation techniques were employed to mask the malicious code within the JavaScript library. This code executed only under certain conditions, primarily targeting the Copay wallet application, leveraging npm environment variables during application build source .

Specific Tools and Tactics

  • Malicious npm Package: Usage of flatmap-stream in propagating malicious code.
  • Code Execution and Control: Execution dynamics exploited by examining package descriptions, silently enacting code during runtime.
  • Data Encryption: Encryption of scripts using AES complicating static analysis detection source .

Indicators of Compromise

  • File-Based Indicators: Presence of flatmap-stream in dependency structures.
  • Network-Based Indicators: Activities directed to copayapi.host:8080 indicating possible malfeasance.
  • Application-Based Indicators: Anomalous builds of Copay applications (5.0.2 through 5.1.0) showing unauthorized alterations source .

Malware Deployment

The malware specifically targeted the Copay cryptocurrency wallet to discreetly extract private keys and cryptocurrency holdings when thresholds, like over 100 BTC or 1000 BCH, were satisfied source .

Progression of Attack

  1. Access Assignment: Obtained through social engineering of the original maintainer source .
  2. Malicious Code Injection: flatmap-stream allowed with copious environmental condition checks, using npm_package_description, activating unauthorized exfiltration unnoticed.

Unexpected Approach

The breach presented an advanced supply chain attack, exploiting dependency management practices. It highlighted vulnerabilities by using build environment variables as decryption tools source .

Impact Assessment

Summary of Immediate Damage

  • Timeline: Breach occurred in November 2018 with extended exposure before detection.
  • Technical Summary: The breach exploited the event-stream and flatmap-stream packages in the Node.js ecosystem. It embedded malicious code in Copay wallet versions 5.0.2 to 5.1.0, permitting unauthorized access to users’ private keys and cryptocurrency holdings, with malicious transactions traced back to servers in Kuala Lumpur source .

Potential Long-term Repercussions

  • User Confidence Decline: Trust deterioration in Copay and similar wallets, encouraging significant reevaluation by users of open-source digital wallets.
  • Regulatory and Development Strain: The breach increased pressure for comprehensive security protocols on third-party dependencies, possibly accelerating regulatory demands on digital wallets source .

Quantifiable Losses

  • Financial Impact: Specific financial losses remain unspecified, however, the private key compromise suggests high-value theft source .
  • Compromised Data Types: Sensitive data, including private keys and linked cryptocurrency balances, was compromised source .

Industry-Wide and Socio-Economic Impacts

  • Exposed Vulnerabilities: Underscored flaws in the open-source software model, highlighting the acute need for enhanced security protocols for third-party library usage source .
  • Market Repercussions: Potential for reduced investor confidence impacting cryptocurrency adoption rates and contributing to market volatility source .

Similar Incidents

Parallels to incidents such as the Mt. Gox breach and SolarWinds attack reiterate vulnerabilities within software supply chain integrity. Despite differences, Copay’s breach illustrates similar systemic weaknesses source .

Reputational Consequences

  • Organization Credibility: Damage to Copay’s credibility, accompanied by skepticism toward BitPay’s security practices, could reduce user engagement and market share source .
  • Security Assurance: To restore trust, transparent security enhancements and detailed post-breach evaluations are imperative source .

Noted Information Gaps

  • Financial Impact Specifics: Lack of explicit financial figures hinders comprehensive evaluation source .
  • User Impact Details: Absence of detailed user impact metrics and behavioral changes post-breach remains unclear source .

Recommendations and Prevention

Implement Secure Dependency Management

  • Description: Utilize lockfiles, such as package-lock.json or yarn.lock, to enforce consistent package versions and perform regular dependency audits using tools like npm audit or Snyk.
  • Rationale: The breach resulted from a malicious modification in the event-stream package including flatmap-stream. Lockfiles and audits ensure dependencies are not altered maliciously.
  • Implementation Example: Integrate SHA-256 cryptographic checksums for package integrity verification within CI/CD pipelines.

Establish Comprehensive Code Review

  • Description: Require mandatory peer reviews along with automated security scanning frameworks for all code submissions, especially third-party libraries.
  • Rationale: Rigorous code review processes can detect unusual patterns and potential vulnerabilities, preventing malicious code integration.
  • Implementation Example: Implement GitHub Pull Requests requiring peer approvals, integrating tools like SonarQube for automated code analysis.

Adopt a Secure Development Lifecycle (SDLC)

  • Description: Embed security practices throughout the software development lifecycle, including threat modeling and secure coding standards.
  • Rationale: Incorporating security in each development phase anticipates and mitigates vulnerabilities, especially those related to dependency management.
  • Implementation Example: Utilize DevSecOps frameworks for continuous security assessments across the software lifecycle.

Enhance Access and Permission Controls

  • Description: Implement stringent access controls, limiting permissions to essential personnel and conducting regular audits.
  • Rationale: Unauthorized access within event-stream facilitated the breach. Role-Based Access Controls (RBAC) minimize such risks.
  • Implementation Example: Use systems like AWS IAM or GitHub’s team management features to define permissions and perform regular audits.

Establish Incident Response and Monitoring

  • Description: Build a comprehensive incident response strategy and implement runtime application security monitoring (RASM) tools for abnormal activity tracking.
  • Rationale: Early detection of anomalous activity helps mitigate breach impact swiftly.
  • Implementation Example: Deploy solutions like Splunk or ELK Stack for real-time monitoring and rapid security incident responses.

Enforce Cryptographic Signatures

  • Description: Mandate use of cryptographic signatures for internal and external code integrity verification before deployment.
  • Rationale: Digital signatures offer assurance of code authenticity and integrity, making injection of malicious code difficult.
  • Implementation Example: Implement automated GPG keys for signing and verifying packages in build processes.

These recommendations collectively enhance security by supporting robust dependency management and access controls, reducing incident risks similar to the Copay breach. By implementing these strategies, a secure software development and deployment environment is maintained.

Conclusion

Technical Timeline and Mechanisms

Breach Period

Malicious code was present from September to November 2018, enabling unauthorized data extraction from users’ wallets source .

Attack Methodology

  • Malicious Code Injection: flatmap-stream introduced malicious code within event-stream, facilitating private key extraction and unauthorized asset movements source .
  • Exploitation Framework: Exploited a privilege elevation due to active maintainer oversight during event-stream control transfer source .

Lessons for Industry Standards and Practices

Supply Chain Security

The breach underscores the necessity for stringent supply chain security practices. Comprehensive vetting for third-party libraries, mandatory package signing, and automated dependency scanning tools are crucial security enhancements source .

Improving Security Posture

  • Regular Vulnerability Audits: Conduct periodic audits on third-party libraries using automation tools capable of rapid threat identification source .
  • Version Pinning and Testing: Adopt version pinning to lock dependencies to known secure versions, buttressed by rigorous testing source .

The Copay breach represents an evolving threat matrix targeting software dependencies in broadly trusted open-source frameworks, signaling a need for enhanced package management protocol source .

  • Social Engineering and Trust Exploits: Future threats may exploit open-source community trust dynamics, necessitating robust package management solutions source .

Positive Security Outcomes

  • Raised Awareness and Cooperative Defense: This incident heightened global awareness, prompting collaboration in the software community to advance security measures and share threat intelligence source .

Data Gaps and Future Insights

The report lacks specific quantitative data on financial loss magnitude and exact affected user base. Post-breach remedial measures by Copay developers are also poorly disclosed. Full disclosure and analysis could facilitate robust future defenses source .

This report was machine-generated with PlanAI using the following sources:

Invariant analysis

InvariantEffectivenessConf.Explanation
Mandatory Hardware Second FactorHighThe initial intrusion vector was a social engineering request by right9ctrl to Dominic Tarr, the original event-stream maintainer, who voluntarily granted publish/maintainer rights due to inactivity - not a phishing or credential-stuffing attack against an authentication system. No stolen password or second factor was involved; the attacker was legitimately granted access by the maintainer himself. A hardware second-factor requirement on npm accounts would not have prevented Tarr from voluntarily transferring maintainer rights to a requester he believed was trustworthy, so this control does not interact with the attack chain as described.
Positive Execution ControlMediumThe malicious payload was not a separate unauthorized executable dropped onto a system; it was code embedded within the flatmap-stream/event-stream dependency that was compiled directly into the officially distributed, already-allow-listed Copay wallet application (versions 5.0.2-5.1.0). Application allow-listing at the endpoint or production-system level would still permit the Copay app to run, since the app itself is the approved binary - the compromise lives inside the approved code via build-time obfuscated, AES-decrypted logic activated through npm_package_description checks. This invariant does not meaningfully interact with a supply-chain code-injection attack that rides inside an already-trusted application.
Egress ControlMediumThe exfiltration of private keys occurred from end-users' own devices running the compromised Copay wallet app (versions 5.0.2-5.1.0), sending data to the attacker's server at 111.90.151.134 / copayapi.host:8080. Egress allow-listing as described protects an organization's own fleet of production servers and employee endpoints, not the millions of independent consumer devices running a distributed cryptocurrency wallet application. BitPay's internal infrastructure was not the channel through which private keys and funds were stolen; the theft happened client-side on user hardware outside BitPay's controlled environment, so this invariant does not interact with the actual exfiltration step of this attack chain.
Supply Chain AgingHighThis invariant maps directly onto the root cause: the malicious flatmap-stream 0.1.1 was released October 5, 2018, and incorporated into event-stream 3.3.6, but the malicious behavior and code injection were not publicly identified until November 19-20, 2018, and the packages were pulled November 26, 2018 - roughly 6-7 weeks later. A 30-day (or even shorter) mandatory aging period before importing new open-source dependency versions would have prevented BitPay/Copay from including the compromised event-stream/flatmap-stream version in Copay 5.0.2-5.1.0 at all, since the community-driven discovery and removal (per the report's timeline) occurred well within that window, stopping the initial compromise entirely.

Scored in assets/invariants/Copay_Cryptocurrency_Wallet_Breach_November_2018_final.yaml — the same rows the leaderboard counts.

Read the invariant that would have stopped this

Comments

Now playing Bandcamp