ultra-base64-math@1.0.2
Malicious code in ultra-base64-math (npm)
Analysis
Package ultra-base64-math@1.0.2 ships two identical 52KB javascript-obfuscator-obfuscated files (restored_script.js and test.js) alongside a trivial 84-byte entry point that exports only a hello() function. The obfuscated files contain XOR-decoding routines and a large base64-encoded payload assembled via runtime string-array lookups. The package declares dependencies on stub packages impersonating Node.js core modules (child_process@^1.0.2, https@^1.0.0, os@^0.1.2, path@^0.12.7) and on axios@^1.13.5, a version associated with malicious activity. The bundled obfuscated code is not invoked by the entry point and no install hooks are present, leaving the payload dormant. The package has no description or repository URL.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:42 AM
- analyzed
- Jun 15, 2026, 10:45 AM
Related advisories
- ui-core-system@1.0.3
- @servicetitan/anvil2-ext-mwv@0.0.9
- akamai-sensorv3@1.0.0
- ai-pro-sdk@2.0.3
- txs-data@1.0.1
- toast-react-slider@1.0.0
- textify-kit@1.0.0
- tailwind-core@4.3.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.