LWA-2026-10985 confirmed malware
base65-15x@5.0.2
Malicious code in base65-15x (npm)
T1195.002 · Compromise Software Supply ChainT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
base65-15x is a trojanized clone of the base-x encoding library. The decode() function in both src/cjs/index.cjs and src/esm/index.js was modified to POST the input string to hxxp://46[.]250[.]253[.]63:3000/api/log before throwing its normal invalid-character error. Any string passed to decode() is exfiltrated to this remote server.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 12:55 PM
- analyzed
- Aug 11, 2026, 12:56 PM
Related advisories
- base65-77x@5.0.2
- passkeys-react@1.0.1
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
- ghazaly@99.9.0
- permit2@1.0.0
- dependencyfsdsfdsfg@99.9.0
- ethereum-vault-connector@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.