
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-j8qr-rvcv-crhv) was discovered in the electron-native-notify package, which contained malicious code targeting cryptocurrency wallet users. The attack was identified on June 4, 2019, specifically affecting Komodo's Agama wallet. The malicious package was designed to steal cryptocurrency wallet seeds and upload them to a remote server, effectively compromising users' wallets (GitHub Advisory, NPM Blog).
The attack utilized a sophisticated pattern where the attacker published a seemingly legitimate package (electron-native-notify) to npm, waited for the target application to implement it, and then updated it with malicious code. The malicious version was introduced in version 1.1.6 on March 23, 2019, after the package was integrated into the EasyDEX-GUI application used by the Agama wallet. The vulnerability affected all versions of electron-native-notify, with no patched versions available (NPM Blog).
The vulnerability resulted in the potential compromise of approximately 1 million KMD (Komodo) tokens and 96 BTC. This represented less than one percent of the circulating supply of KMD and roughly 0.5% of the total supply. The attack specifically targeted cryptocurrency assets stored in Komodo's Agama wallet, with the attacker gaining access to users' wallet seeds (Komodo Platform).
The vulnerability was actively exploited in the wild. The attacker implemented a sophisticated approach by first making legitimate contributions to the Agama repository before introducing the malicious code. The exploit involved collecting user seed phrases and storing them on a publicly accessible server, making the funds vulnerable to theft (NPM Blog).
Upon discovery, the Komodo team took immediate action by moving funds to secure wallets to protect users. The team secured approximately 8 million KMD and 96 BTC. Users affected by the vulnerability were advised to complete a Missing Funds Claim Form to reclaim their assets. The Komodo team implemented a verification process requiring users to send a small transaction from their compromised wallet to prove ownership. Additionally, Komodo's Lead Developer pledged 500,000 KMD to compensate affected users (Komodo Platform).
The npm security team collaborated with Komodo to address the threat promptly. The Komodo community showed understanding and patience during the incident resolution. The Verus Coin team, which maintains a separate version of Agama wallet, was acknowledged for providing a secure alternative for users. The incident led to Komodo developing a new wallet called AtomicDEX with enhanced security measures (Komodo Platform).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."