The electron-native-notify npm Supply Chain Attack

Updated 5 Oct 2026 · Incident date 23 Mar 2019 · npm

Packageelectron-native-notify 1.1.5 -> 1.1.6
Filethe package's main entry module

On 23 March 2019, the attacker published electron-native-notify 1.1.6 on npm with a malicious payload. The package was a dependency of the Agama cryptocurrency wallet from Komodo. The payload stole wallet seed phrases.

npm and Komodo put the value at risk at over 13 million US dollars. Version 1.1.5 was clean.

What happened

An attacker built trust with a harmless package and then added malicious code. According to npm, the attacker published a package that looked useful and later updated it with a malicious payload. Komodo states that the attacker spent several months making useful contributions before the code went in.

The timeline from npm and Snyk:

The code sent an HTTP GET request to a Heroku endpoint and downloaded a payload. The payload ran, then sent the wallet seed to the same server when a user entered it. Snyk also reports a later version, 1.2.0, deployed between 16 April and 11 May 2019.

Komodo reports that about one million KMD were taken, which is less than 1 percent of the circulating supply. The Komodo team moved about 8 million KMD and 96 BTC to safe storage. Only Komodo's Agama build was affected. The Verus Coin version was not. The KMD blockchain itself was not affected.

Vigilance compares the version you trust with the new one. Version 1.1.6 added code that fetches and runs a remote payload, and Vigilance reports the file that gained that capability. See the scan block below.

Affected versions

Indicators of compromise

How to check

Search the tree for the package.

npm ls electron-native-notify
grep -rn "electron-native-notify" package.json package-lock.json yarn.lock 2>/dev/null

Also search proxy logs for updatecheck.herokuapp.com. For Agama, a user must check the wallet version and the date of the install.

What to do now

  1. Remove electron-native-notify from every project and rebuild.
  2. Agama users: Snyk advises moving all funds to a new address as soon as possible. Generate a new seed on a clean machine.
  3. Komodo asked affected users to file a Missing Funds Claim Form and to send a small test transaction from the old wallet to prove ownership.
  4. Block the Heroku endpoint.
  5. Run npm audit. npm added automatic notices after this incident.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old electron-native-notify-1.1.5 --new electron-native-notify-1.1.6
files scanned: 12

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    package.json
           It now downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which electron-native-notify version was malicious?

Version 1.1.6, published on 23 March 2019, was malicious. Snyk also reports a later version, 1.2.0, with the malicious code. Version 1.1.5 was clean.

Did the electron-native-notify attack steal cryptocurrency?

Yes. It targeted seed phrases in the Komodo Agama wallet. Komodo reports about one million KMD were taken.

Sources

  1. blog.npmjs.org/post/185397814280/plot-to-steal-cryptocurrency-foiled-by-the-npm
  2. snyk.io/blog/yet-another-malicious-package-found-in-npm-targeting-cryptocurrency-wallets/
  3. komodoplatform.com/en/blog/update-agama-vulnerability/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free