LWA-2026-4223 confirmed malware
node-bs58.js@4.0.4
Malicious code in node-bs58.js (npm)
T1195.002 · Compromise Software Supply ChainT1005 · Data from Local SystemT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Combosquat of the legitimate `bs58` Base58 encoding library. The `decode()` function wraps `bs58.decode()` with a `sendMessage()` call that POSTs the user-supplied input to Telegram via hardcoded bot token ([redacted-credential]) and chat ID (7631491367) at api[.]telegram[.]org. Any private key, wallet seed, or sensitive data a user passes to decode() is silently exfiltrated to the attacker's Telegram C2 channel (group t[.]me/+IDl6XgFBZdI1ZjZh). Publisher [account] Package also ships `!bs58-private-key[.]zip` containing a bundled npm project.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:46 AM
- analyzed
- Jun 11, 2026, 09:49 AM
Related advisories
- hex-type@3.0.2
- wallet-sdk-9@3.7.73
- move-bcs-codec@1.0.0
- python-bitcoinlib@1.0.2
- simple-date-formatter-new-6@1.0.0
- simple-date-formatter-new-3@1.0.0
- simple-date-formatter-util-13@1.0.0
- simple-date-formatter-util-11@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.