Account Takeover 2018 Incident #1 SNYK-JS-EVENTSTREAM-72638

event-stream / flatmap-stream

Estimated Financial Impact
$1M+ crypto theft
Blast Radius
2M weekly downloads; BitPay Copay wallet

What Happened

Attacker social-engineered maintainer Dominic Tarr into handing over publishing rights to event-stream (~2M weekly downloads). A malicious dependency (flatmap-stream) was injected targeting BitPay's Copay Bitcoin wallet to steal private keys from accounts holding over 100 BTC. The malicious version was downloaded approximately 8 million times over 2.5 months before discovery.

Sources: Dominic Tarr statement · BitPay advisory · npm postmortem

✓

Risk Guard: Caught

SOURCE_SINGLE_CONTRIBUTOR flagged maintainer transfer months before; PACKAGE_INSTALL_SCRIPTS caught postinstall payload

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_INSTALL_SCRIPTSPACKAGE_PAST_MALWARESOURCE_SINGLE_CONTRIBUTOR

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught SOURCE_SINGLE_CONTRIBUTOR flagged maintainer transfer months before; PACKAGE_INSTALL_SCRIPTS caught postinstall payload
Sonatype (Nexus) Partial Firewall may block if signature added; missed social engineering precondition
Socket Caught Behavioral analysis detects malicious flatmap-stream payload
Snyk Missed No malware detection; CVE-only
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← Previous ua-parser-js hijack →