Malicious code in base65-33x (npm)
Malware
Published
Aug 11, 2026
to the GitHub Advisory Database
•
Updated Aug 11, 2026
Description
Published to the GitHub Advisory Database
Aug 11, 2026
Reviewed
Aug 11, 2026
Last updated
Aug 11, 2026
Source: amazon-inspector (f4e22e29bf42b32b80c5336d5f38d10d96879c84f162d86565289b588253589b)
Package name resembles the popular
base-xencoder/decoder. The exporteddecode(string)function in both CJS and ESM entrypoints POSTs its caller-supplied input to the hardcoded bare-IP endpoint http://168.231.81.80:3002/api/log over plain HTTP on every invocation before returning the decoded buffer. Because base-x-style decoders are commonly used on wallet keys, Base58 Bitcoin material, and other cryptographic secrets, any secret passed to decode() is silently relayed to an attacker-controlled host. Bothrequireandimportconsumers trigger the same relay path.Credit: OpenSSF (source)
References