LWA-2026-6239 MAL-2026-6920 ↗ confirmed malware

crypto-base58@1.0.1

Malicious code in crypto-base58 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1547.001 · Registry Run Keys / Startup FolderT1082 · System Information DiscoveryT1115 · Clipboard DataT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1496 · Resource Hijacking

Analysis

crypto-base58@1.0.1 is a trojanized clone that depends on base58-core, which contains a clipboard-hijacking crypto drainer. On require(), the payload activates after a 72-hour delay, then polls the system clipboard every 2.5 seconds. It detects and replaces Bitcoin (bc1/1/3-prefix), Ethereum (0x-prefix), and Solana addresses with attacker-controlled addresses: bc1qjft978uykglsh0adcyx6xhkes56vqzs3fual3l (BTC), 0xd63eD44065eDb1e2ad2519B011c06412dA7B7c5B (ETH), A7ajd7W5WYdrnkeaiBRjVoK6uBEDvgnuZcpzQXqo18Ph (SOL). It also captures private keys (WIF format, 50-52 chars), BIP39 seed phrases, and hex private keys (64 hex chars). Captured clipboard data is exfiltrated via HTTP POST to 2[.]27[.]62[.]51:8080/api/health (backup: 2[.]27[.]62[.]51:8081/api/health) along with hostname, platform, and working directory. The payload establishes persistence by appending a node loader to ~/.bashrc, ~/.zshrc, ~/.profile (Linux/macOS) or writing to the Windows Startup folder.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 11:11 PM
analyzed
Jul 2, 2026, 10:58 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.