LWA-2026-4333 confirmed malware
npm-bs58.js@2.0.2
Malicious code in npm-bs58.js (npm)
T1195.002 · Compromise Software Supply ChainT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
npm-bs58.js@2.0.2 is a combosquat of the bs58 cryptocurrency library. Its sole dependency, base128-x58, contains a trojanized decode() function: when a victim decodes a base58 string (such as a Bitcoin address or private key), the function silently POSTs that string to a Telegram bot API sendMessage endpoint before returning the decoded value, exfiltrating any base58-encoded data to the attacker's Telegram channel. There are no lifecycle hooks; exfiltration occurs at runtime whenever the library is used, targeting blockchain developers.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 03:09 PM
- analyzed
- Jun 11, 2026, 03:35 PM
Related advisories
- noon-contracts@1.0.0
- ts-eslint-helper@4.0.1
- ts-ecro@0.0.6
- parket-slot@0.0.6
- n8n-nodes-pentest-rce@1.0.1
- mw-filesystem-events-nodream_compat@99.99.99
- motion-lib@2.3.5
- hex-type@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.