LWA-2026-10984 confirmed malware

base65-77x@5.0.2

Malicious code in base65-77x (npm)

T1195.002 · Compromise Software Supply ChainT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

base65-77x is a trojanized clone of the base-x encoding library. Its decode() function in src/cjs/index.cjs and src/esm/index.js has been modified to POST the string being decoded to hxxp://46[.]250[.]253[.]63:3000/api/log via fetch before returning the result. Any application that uses this library to decode base64/base58 strings silently sends the decoded content to that remote server, exfiltrating whatever data the host application decodes.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 12:55 PM
analyzed
Aug 11, 2026, 12:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.