LWA-2026-10984 confirmed malware
base65-77x@5.0.2
Malicious code in base65-77x (npm)
T1195.002 · Compromise Software Supply ChainT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
base65-77x is a trojanized clone of the base-x encoding library. Its decode() function in src/cjs/index.cjs and src/esm/index.js has been modified to POST the string being decoded to hxxp://46[.]250[.]253[.]63:3000/api/log via fetch before returning the result. Any application that uses this library to decode base64/base58 strings silently sends the decoded content to that remote server, exfiltrating whatever data the host application decodes.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 12:55 PM
- analyzed
- Aug 11, 2026, 12:55 PM
Related advisories
- passkeys-react@1.0.1
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
- ghazaly@99.9.0
- permit2@1.0.0
- dependencyfsdsfdsfg@99.9.0
- ethereum-vault-connector@1.0.0
- @aerodrome-finance/slipstream@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.