Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in base65-12x (npm)

0
Critical
Published: 08/11/2026 (08/11/2026, 16:40:07 UTC)
Source: GCVE Database
Product: base65-12x

Description

The npm package base65-12x is a malicious typosquatting package that mimics the legitimate base-x encoding library. It contains a large obfuscated code block that installs a virtual machine dispatcher on the global scope, manipulates JavaScript object properties, and performs network fetch operations immediately upon import or require. This behavior is unnecessary for a base-encoding library and indicates malicious intent. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system should be rotated. Removal of the package does not guarantee full remediation due to potential persistent compromise.

Affected software

npmghsa
base65-12x
Affected versions
=5.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 00:59:47 UTC

Technical Analysis

The base65-12x npm package is a typosquatting malicious package that reuses the legitimate base-x repository homepage to appear legitimate. Both its CommonJS and ESM entry points include a roughly 123 KB obfuscated payload that sets up a VM-style dispatcher on the globalThis object, alters Object.defineProperty and __proto__, and includes multiple network fetch calls. This payload executes unconditionally when the package is imported or required, enabling remote code execution and persistent compromise. The package's functionality as a base-encoding library does not justify this behavior, confirming its malicious nature. Systems with this package installed are at high risk of full compromise.

Potential Impact

Systems that have installed or are running the base65-12x package are considered fully compromised. The malicious payload grants an attacker extensive control over the affected system, potentially exposing all stored secrets and keys. Because the malicious code runs immediately upon module import, it can execute arbitrary code and perform network operations without user consent. Even after removal of the package, the system may remain compromised due to persistent malware installed by the payload.

Mitigation Recommendations

Immediate removal of the base65-12x package is recommended. All secrets, credentials, and keys stored on the affected system should be rotated from a separate, uncompromised device. Due to the high likelihood of full system compromise, a complete system rebuild or forensic investigation is advised to ensure all malicious artifacts are eradicated. There is no official patch or fix for this malicious package; prevention relies on avoiding installation and using trusted package sources.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13746
Osv Schema Version
1.7.4
Aliases
["GHSA-c4w7-m3hx-xx75"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7bc14ebf8831d539b15639

Added to database: 08/12/2026, 00:41:50 UTC

Last enriched: 08/12/2026, 00:59:47 UTC

Last updated: 08/12/2026, 01:49:14 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses