Malicious code in base65-12x (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (79b553d84d7f4dc5347840ddb97f16738eed2e52ac9757b48d2cb31ba1af7122) The package name base65-12x typosquats the popular base-x base-encoding library and reuses base-x's repository as its homepage. Both the CJS entry (index.js around line 116) and the ESM entry (src/esm/index.js around line 114) append an approximately 123 KB top-level obfuscated block after a copy of the legitimate base-x source. The block installs a VM-style dispatcher on globalThis (registries named vmr_3f4688 and vmw_bf472f), manipulates Object.defineProperty and __proto__, and contains multiple fetch references, so a network-capable code path is wired up and runs unconditionally when a consumer requires or imports the package. A base-encoding library has no functional need for a large globalThis-poisoning obfuscated VM with network fetch at module top level; the payload is duplicated across both module systems so it fires for CJS and ESM consumers alike. ## Source: ghsa-malware (4891fcf0d0e6192d9be14faf68411bd475129a1245b5c863a9daaa6f66e66166) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
AI Analysis
Technical Summary
The base65-12x npm package is a typosquatting malicious package that reuses the legitimate base-x repository homepage to appear legitimate. Both its CommonJS and ESM entry points include a roughly 123 KB obfuscated payload that sets up a VM-style dispatcher on the globalThis object, alters Object.defineProperty and __proto__, and includes multiple network fetch calls. This payload executes unconditionally when the package is imported or required, enabling remote code execution and persistent compromise. The package's functionality as a base-encoding library does not justify this behavior, confirming its malicious nature. Systems with this package installed are at high risk of full compromise.
Potential Impact
Systems that have installed or are running the base65-12x package are considered fully compromised. The malicious payload grants an attacker extensive control over the affected system, potentially exposing all stored secrets and keys. Because the malicious code runs immediately upon module import, it can execute arbitrary code and perform network operations without user consent. Even after removal of the package, the system may remain compromised due to persistent malware installed by the payload.
Mitigation Recommendations
Immediate removal of the base65-12x package is recommended. All secrets, credentials, and keys stored on the affected system should be rotated from a separate, uncompromised device. Due to the high likelihood of full system compromise, a complete system rebuild or forensic investigation is advised to ensure all malicious artifacts are eradicated. There is no official patch or fix for this malicious package; prevention relies on avoiding installation and using trusted package sources.
Malicious code in base65-12x (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (79b553d84d7f4dc5347840ddb97f16738eed2e52ac9757b48d2cb31ba1af7122) The package name base65-12x typosquats the popular base-x base-encoding library and reuses base-x's repository as its homepage. Both the CJS entry (index.js around line 116) and the ESM entry (src/esm/index.js around line 114) append an approximately 123 KB top-level obfuscated block after a copy of the legitimate base-x source. The block installs a VM-style dispatcher on globalThis (registries named vmr_3f4688 and vmw_bf472f), manipulates Object.defineProperty and __proto__, and contains multiple fetch references, so a network-capable code path is wired up and runs unconditionally when a consumer requires or imports the package. A base-encoding library has no functional need for a large globalThis-poisoning obfuscated VM with network fetch at module top level; the payload is duplicated across both module systems so it fires for CJS and ESM consumers alike. ## Source: ghsa-malware (4891fcf0d0e6192d9be14faf68411bd475129a1245b5c863a9daaa6f66e66166) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The base65-12x npm package is a typosquatting malicious package that reuses the legitimate base-x repository homepage to appear legitimate. Both its CommonJS and ESM entry points include a roughly 123 KB obfuscated payload that sets up a VM-style dispatcher on the globalThis object, alters Object.defineProperty and __proto__, and includes multiple network fetch calls. This payload executes unconditionally when the package is imported or required, enabling remote code execution and persistent compromise. The package's functionality as a base-encoding library does not justify this behavior, confirming its malicious nature. Systems with this package installed are at high risk of full compromise.
Potential Impact
Systems that have installed or are running the base65-12x package are considered fully compromised. The malicious payload grants an attacker extensive control over the affected system, potentially exposing all stored secrets and keys. Because the malicious code runs immediately upon module import, it can execute arbitrary code and perform network operations without user consent. Even after removal of the package, the system may remain compromised due to persistent malware installed by the payload.
Mitigation Recommendations
Immediate removal of the base65-12x package is recommended. All secrets, credentials, and keys stored on the affected system should be rotated from a separate, uncompromised device. Due to the high likelihood of full system compromise, a complete system rebuild or forensic investigation is advised to ensure all malicious artifacts are eradicated. There is no official patch or fix for this malicious package; prevention relies on avoiding installation and using trusted package sources.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13746
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-c4w7-m3hx-xx75"]
- Ecosystems
- ["npm"]
Threat ID: 6a7bc14ebf8831d539b15639
Added to database: 08/12/2026, 00:41:50 UTC
Last enriched: 08/12/2026, 00:59:47 UTC
Last updated: 09/24/2026, 18:16:48 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.