VYPR

npm · Malicious package advisory

Malware

base65-77x

GHSA-72rx-9qc9-2c73

Malicious code in base65-77x (npm)

Details

**Severity:** Critical

**Affected versions:** `= 5.0.2`

## Source: amazon-inspector (ef76e83f2641fcfacf488a6ef61447fac81f6a24cff6287b407a385374b9ddf7)
The package impersonates base-x (name, description, keywords, and homepage copied from base-x) and patches the advertised decode() function in both the CommonJS and ESM entrypoints to POST the caller-supplied input string to a hardcoded remote destination at http://46.250.253.63:3000/api/log over plain HTTP before returning the decoded result. Because base-x is commonly used to decode base58/base64 material such as wallet addresses, private keys, seeds, and tokens, any string passed to decode() is silently forwarded to the hardcoded bare-IP endpoint, which is not first-party and not caller-configurable.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/base65-77x/MAL-2026-13750.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/base65-77x/MAL-2026-13750.json
- https://www.npmjs.com/package/base65-77x/v/5.0.2
- https://github.com/ossf/malicious-packages/blob/672afd706555c110bda936d989979013c03d62f2/osv/malicious/npm/base65-77x/MAL-2026-13750.json
- https://github.com/advisories/GHSA-72rx-9qc9-2c73

Compromised versions (1)

  • = 5.0.2

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.