LWA-2026-10988 confirmed malware

base65-33x@5.0.2

Malicious code in base65-33x (npm)

T1195.002 · Compromise Software Supply ChainT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

base65-33x is a trojanized clone of the base-x encoding library. Its decode() function has been modified to POST the string being decoded to a remote server at hxxp://168[.]231[.]81[.]80:3002/api/log via fetch, exfiltrating any data decoded through the library to that endpoint. Both the CommonJS (src/cjs/index.cjs) and ESM (src/esm/index.js) builds contain the injected exfiltration code.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 01:22 PM
analyzed
Aug 11, 2026, 01:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.