LWA-2026-10988 confirmed malware
base65-33x@5.0.2
Malicious code in base65-33x (npm)
T1195.002 · Compromise Software Supply ChainT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service
Analysis
base65-33x is a trojanized clone of the base-x encoding library. Its decode() function has been modified to POST the string being decoded to a remote server at hxxp://168[.]231[.]81[.]80:3002/api/log via fetch, exfiltrating any data decoded through the library to that endpoint. Both the CommonJS (src/cjs/index.cjs) and ESM (src/esm/index.js) builds contain the injected exfiltration code.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 01:22 PM
- analyzed
- Aug 11, 2026, 01:24 PM
Related advisories
- developer-dashboard@1.0.2
- passport811@1.0.0
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- sme-rko-finance-front-operations-pegasus@35.8.1
- map-streak-kit@1.0.0
- streak-map-kit@1.0.0
- dolyame-ui-attachfile@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.