LWA-2026-4333 confirmed malware

npm-bs58.js@2.0.2

Malicious code in npm-bs58.js (npm)

T1195.002 · Compromise Software Supply ChainT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

npm-bs58.js@2.0.2 is a combosquat of the bs58 cryptocurrency library. Its sole dependency, base128-x58, contains a trojanized decode() function: when a victim decodes a base58 string (such as a Bitcoin address or private key), the function silently POSTs that string to a Telegram bot API sendMessage endpoint before returning the decoded value, exfiltrating any base58-encoded data to the attacker's Telegram channel. There are no lifecycle hooks; exfiltration occurs at runtime whenever the library is used, targeting blockchain developers.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 03:09 PM
analyzed
Jun 11, 2026, 03:35 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.