LWA-2026-10985 confirmed malware

base65-15x@5.0.2

Malicious code in base65-15x (npm)

T1195.002 · Compromise Software Supply ChainT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

base65-15x is a trojanized clone of the base-x encoding library. The decode() function in both src/cjs/index.cjs and src/esm/index.js was modified to POST the input string to hxxp://46[.]250[.]253[.]63:3000/api/log before throwing its normal invalid-character error. Any string passed to decode() is exfiltrated to this remote server.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 12:55 PM
analyzed
Aug 11, 2026, 12:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.