base58-cli@1.0.0
Malicious code in base58-cli (npm)
Analysis
base58-cli@1.0.0 is a CLI wrapper that, at import time, triggers a clipboard hijacker in its dependency base58-core. After a 72-hour delay from installation, the payload establishes persistence by appending a re-loader to ~/.bashrc, ~/.zshrc, or ~/.profile (Linux/macOS) or writing to the Windows Startup folder, then polls the clipboard every 2.5 seconds. It scans clipboard content for cryptocurrency wallet addresses (BTC, ETH, Solana), private keys (WIF format, hex keys, seed phrases), and HTTP POSTs captured data to 2[.]27[.]62[.]51:8080/api/health (backup: 2[.]27[.]62[.]51:8081/api/health). It also replaces BTC addresses with bc1qjft978uykglsh0adcyx6xhkes56vqzs3fual3l, ETH addresses with 0xd63eD44065eDb1e2ad2519B011c06412dA7B7c5B, and Solana addresses with A7ajd7W5WYdrnkeaiBRjVoK6uBEDvgnuZcpzQXqo18Ph to redirect crypto transactions to attacker-controlled wallets.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 01:50 AM
- analyzed
- Jun 25, 2026, 01:51 AM
Related advisories
- @wacrot/infra-data-kit@2.1.4
- noon-contracts@1.0.0
- wormgpt-cli@1.0.1
- streak-metrics-math@1.0.1
- streak-metrics-core@1.0.0
- @epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.0-pentest
- zod-pino@1.0.122
- shadxino@1.0.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.