Vulnerability DatabaseGHSA-j8qr-rvcv-crhv

GHSA-j8qr-rvcv-crhv
JavaScript vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-j8qr-rvcv-crhv) was discovered in the electron-native-notify package, which contained malicious code targeting cryptocurrency wallet users. The attack was identified on June 4, 2019, specifically affecting Komodo's Agama wallet. The malicious package was designed to steal cryptocurrency wallet seeds and upload them to a remote server, effectively compromising users' wallets (GitHub Advisory, NPM Blog).

Technical details

The attack utilized a sophisticated pattern where the attacker published a seemingly legitimate package (electron-native-notify) to npm, waited for the target application to implement it, and then updated it with malicious code. The malicious version was introduced in version 1.1.6 on March 23, 2019, after the package was integrated into the EasyDEX-GUI application used by the Agama wallet. The vulnerability affected all versions of electron-native-notify, with no patched versions available (NPM Blog).

Impact

The vulnerability resulted in the potential compromise of approximately 1 million KMD (Komodo) tokens and 96 BTC. This represented less than one percent of the circulating supply of KMD and roughly 0.5% of the total supply. The attack specifically targeted cryptocurrency assets stored in Komodo's Agama wallet, with the attacker gaining access to users' wallet seeds (Komodo Platform).

Exploitability

The vulnerability was actively exploited in the wild. The attacker implemented a sophisticated approach by first making legitimate contributions to the Agama repository before introducing the malicious code. The exploit involved collecting user seed phrases and storing them on a publicly accessible server, making the funds vulnerable to theft (NPM Blog).

Mitigation and workarounds

Upon discovery, the Komodo team took immediate action by moving funds to secure wallets to protect users. The team secured approximately 8 million KMD and 96 BTC. Users affected by the vulnerability were advised to complete a Missing Funds Claim Form to reclaim their assets. The Komodo team implemented a verification process requiring users to send a small transaction from their compromised wallet to prove ownership. Additionally, Komodo's Lead Developer pledged 500,000 KMD to compensate affected users (Komodo Platform).

Community reactions

The npm security team collaborated with Komodo to address the threat promptly. The Komodo community showed understanding and patience during the incident resolution. The Verus Coin team, which maintains a separate version of Agama wallet, was acknowledged for providing a secure alternative for users. The incident led to Komodo developing a new wallet called AtomicDEX with enhanced security measures (Komodo Platform).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-vx52-2968-3vc6HIGH7.4
  • JavaScript logoJavaScript
  • pnpm
NoYesSep 01, 2026
GHSA-2rx9-3g3h-c2jvHIGH7.1
  • JavaScript logoJavaScript
  • pnpm
NoYesSep 01, 2026
GHSA-cp6q-959q-f8rhMEDIUM6.4
  • JavaScript logoJavaScript
  • @tiptap/core
NoYesSep 02, 2026
GHSA-p498-v437-472gMEDIUM5.7
  • JavaScript logoJavaScript
  • @humanfs/node
NoYesSep 02, 2026
CVE-2026-84371MEDIUM5.4
  • JavaScript logoJavaScript
  • cockpit-image-builder
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management