LWA-2026-5365 confirmed malware

ultra-base64-math@1.0.2

Malicious code in ultra-base64-math (npm)

T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or InformationT1027.010 · Command Obfuscation

Analysis

Package ultra-base64-math@1.0.2 ships two identical 52KB javascript-obfuscator-obfuscated files (restored_script.js and test.js) alongside a trivial 84-byte entry point that exports only a hello() function. The obfuscated files contain XOR-decoding routines and a large base64-encoded payload assembled via runtime string-array lookups. The package declares dependencies on stub packages impersonating Node.js core modules (child_process@^1.0.2, https@^1.0.0, os@^0.1.2, path@^0.12.7) and on axios@^1.13.5, a version associated with malicious activity. The bundled obfuscated code is not invoked by the entry point and no install hooks are present, leaving the payload dormant. The package has no description or repository URL.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:42 AM
analyzed
Jun 15, 2026, 10:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.