Malicious code in base65-12x (npm)
The npm package base65-12x is a malicious typosquatting package that mimics the legitimate base-x encoding library. It contains a large obfuscated code block that installs a virtual machine dispatcher on the global scope, manipulates JavaScript object properties, and performs network fetch operations immediately upon import or require. This behavior is unnecessary for a base-encoding library and indicates malicious intent. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system should be rotated. Removal of the package does not guarantee full remediation due to potential persistent compromise.
AI Analysis
Technical Summary
The base65-12x npm package is a typosquatting malicious package that reuses the legitimate base-x repository homepage to appear legitimate. Both its CommonJS and ESM entry points include a roughly 123 KB obfuscated payload that sets up a VM-style dispatcher on the globalThis object, alters Object.defineProperty and __proto__, and includes multiple network fetch calls. This payload executes unconditionally when the package is imported or required, enabling remote code execution and persistent compromise. The package's functionality as a base-encoding library does not justify this behavior, confirming its malicious nature. Systems with this package installed are at high risk of full compromise.
Potential Impact
Systems that have installed or are running the base65-12x package are considered fully compromised. The malicious payload grants an attacker extensive control over the affected system, potentially exposing all stored secrets and keys. Because the malicious code runs immediately upon module import, it can execute arbitrary code and perform network operations without user consent. Even after removal of the package, the system may remain compromised due to persistent malware installed by the payload.
Mitigation Recommendations
Immediate removal of the base65-12x package is recommended. All secrets, credentials, and keys stored on the affected system should be rotated from a separate, uncompromised device. Due to the high likelihood of full system compromise, a complete system rebuild or forensic investigation is advised to ensure all malicious artifacts are eradicated. There is no official patch or fix for this malicious package; prevention relies on avoiding installation and using trusted package sources.
Malicious code in base65-12x (npm)
Description
The npm package base65-12x is a malicious typosquatting package that mimics the legitimate base-x encoding library. It contains a large obfuscated code block that installs a virtual machine dispatcher on the global scope, manipulates JavaScript object properties, and performs network fetch operations immediately upon import or require. This behavior is unnecessary for a base-encoding library and indicates malicious intent. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system should be rotated. Removal of the package does not guarantee full remediation due to potential persistent compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The base65-12x npm package is a typosquatting malicious package that reuses the legitimate base-x repository homepage to appear legitimate. Both its CommonJS and ESM entry points include a roughly 123 KB obfuscated payload that sets up a VM-style dispatcher on the globalThis object, alters Object.defineProperty and __proto__, and includes multiple network fetch calls. This payload executes unconditionally when the package is imported or required, enabling remote code execution and persistent compromise. The package's functionality as a base-encoding library does not justify this behavior, confirming its malicious nature. Systems with this package installed are at high risk of full compromise.
Potential Impact
Systems that have installed or are running the base65-12x package are considered fully compromised. The malicious payload grants an attacker extensive control over the affected system, potentially exposing all stored secrets and keys. Because the malicious code runs immediately upon module import, it can execute arbitrary code and perform network operations without user consent. Even after removal of the package, the system may remain compromised due to persistent malware installed by the payload.
Mitigation Recommendations
Immediate removal of the base65-12x package is recommended. All secrets, credentials, and keys stored on the affected system should be rotated from a separate, uncompromised device. Due to the high likelihood of full system compromise, a complete system rebuild or forensic investigation is advised to ensure all malicious artifacts are eradicated. There is no official patch or fix for this malicious package; prevention relies on avoiding installation and using trusted package sources.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13746
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-c4w7-m3hx-xx75"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7bc14ebf8831d539b15639
Added to database: 08/12/2026, 00:41:50 UTC
Last enriched: 08/12/2026, 00:59:47 UTC
Last updated: 08/12/2026, 01:49:14 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.