MAL-2026-13750Malicious code in base65-77x (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | base65-77x | 5.0.2 |
{"modified":"2026-08-11T18:49:32Z","published":"2026-08-11T18:49:32Z","schema_version":"1.7.4","id":"MAL-2026-13750","summary":"Malicious code in base65-77x (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ef76e83f2641fcfacf488a6ef61447fac81f6a24cff6287b407a385374b9ddf7)\nThe package impersonates base-x (name, description, keywords, and homepage copied from base-x) and patches the advertised decode() function in both the CommonJS and ESM entrypoints to POST the caller-supplied input string to a hardcoded remote destination at http://46.250.253.63:3000/api/log over plain HTTP before returning the decoded result. Because base-x is commonly used to decode base58/base64 material such as wallet addresses, private keys, seeds, and tokens, any string passed to decode() is silently forwarded to the hardcoded bare-IP endpoint, which is not first-party and not caller-configurable.\n","affected":[{"package":{"ecosystem":"npm","name":"base65-77x"},"versions":["5.0.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"src/cjs/index.cjs","sha256":"99b4adf8e3995ac7fc8123047a3c1f0b4b8db9c3623117e990a5e451d9e5b6a6","tlsh":"01a1a68e2af611515843b9664a5bf0047378621b662a9f5cfa0fa3107f7052983f6fcf"},{"path":"src/esm/index.js","sha256":"38c43e489c2cca81d6d3972880791ee4b24f96b902e3055803f06cdbca54c522","tlsh":"efa1848e2af610106843b9664a5bf0047378621b662a9f5cfa0fa3107f7152943f6fcf"}],"package_integrity":[{"filename":"base65-77x-5.0.2.tgz","hashes":{"sha1":"0c1e931b86d328a45fde2db8ac68ceeb200c154c","sha512_sri":"sha512-CkF2iwgKoYd4WiuPjWGBp9mTsQRfI6cX5b4zpITq/WqLAyNfWlCjKZDB2AZYhuX8LUQFEqv3sEe1gkpPSawe6A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/base65-77x/v/5.0.2"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017383","import_time":"2026-08-11T18:52:00.940384124Z","modified_time":"2026-08-11T18:49:32Z","sha256":"ef76e83f2641fcfacf488a6ef61447fac81f6a24cff6287b407a385374b9ddf7","source":"amazon-inspector","versions":["5.0.2"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0