base65-85x@5.0.1
Malicious code in base65-85x (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
base65-85x is a combosquat of the legitimate base-x encoding library. The decode() function has been injected with a javascript-obfuscator bytecode virtual machine that, when called, constructs and sends a POST request to hxxp://168[.]231[.]81[.]80:3001/api/log with a JSON body. The C2 endpoint receives data from the compromised environment. The package impersonates the real base-x author (Daniel Cousens) in its metadata but is published by a different account.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 02:42 PM
- analyzed
- Jul 2, 2026, 10:58 AM
Related advisories
- mjs-eslint@7.0.7
- crypto-base58@1.0.1
- @marketfront/actualordersnippetpopup@7.0.0
- date-fns-lite@1.0.6
- consumerweb@2200.4.2
- ecto-cargo-wk1tm59a@99.0.0
- cursed-modules@999.0.0
- auth-next-gen@1.6.29
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.