{"id":"MAL-2026-13748","summary":"Malicious code in base65-15x (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (00fcb69b2f5c7e64ede8df36e3865dad82632ef076c6c2974b568727ec046062)\nbase65-15x is a typosquat of the base-x package. Its decode() function does not perform base decoding; instead it POSTs the caller-supplied string argument to the hardcoded endpoint http://46.250.253.63:3000/api/log over plain HTTP and then throws. Both the CommonJS entry and the ESM build (src/esm/index.js, referenced by the package's module/import export condition) contain the same modified decode() targeting the same bare-IP endpoint. Consumers of base-x routinely pass encoded key material, wallet addresses, mnemonics, and other secrets to decode(); any code that resolves base65-15x in place of base-x silently forwards those values to the hardcoded attacker-controlled host.\n","modified":"2026-08-11T19:00:12.801822875Z","published":"2026-08-11T18:49:11Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017381","import_time":"2026-08-11T18:52:00.616886553Z","modified_time":"2026-08-11T18:49:11Z","sha256":"00fcb69b2f5c7e64ede8df36e3865dad82632ef076c6c2974b568727ec046062","source":"amazon-inspector","versions":["5.0.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/base65-15x/v/5.0.2"}],"affected":[{"package":{"name":"base65-15x","ecosystem":"npm","purl":"pkg:npm/base65-15x"},"versions":["5.0.2"],"database_specific":{"indicators":{"package_integrity":[{"filename":"base65-15x-5.0.2.tgz","hashes":{"sha512_sri":"sha512-9mu2JDrADLII9A/jtMPEtn57bYrkQawSk214yXs4ARlqyLB/cfjacak/+5m6w+czJmO833LoFVczqvbjeikt/g==","sha1":"f64fba72381237abfde44bf11c332e0db53e7d6a"}}],"evidence_files":[{"sha256":"97704a8553c321c030b04c25903c79be385f7455ef9edcf6fbeef38089994ea6","tlsh":"46a1a68e2af611105843b9664a5bf0047378621b662a9f5cfa0fa3107f7052943f6fcf","path":"src/cjs/index.cjs"},{"sha256":"3be123ac6db00bd9c36edb73babd313cf39609bc0b629bc73fd397bd1c52a2cc","tlsh":"5c91848e2af611106843b9664a5be0047378621b662a9f5cfa0fa3107f7052943f6fcf","path":"src/esm/index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/base65-15x/MAL-2026-13748.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}