Skip to main content

Malicious code in base65-12x (npm)

0
Critical
Published: 08/11/2026 (08/11/2026, 16:40:07 UTC)
Source: GCVE Database
Product: base65-12x

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (79b553d84d7f4dc5347840ddb97f16738eed2e52ac9757b48d2cb31ba1af7122) The package name base65-12x typosquats the popular base-x base-encoding library and reuses base-x's repository as its homepage. Both the CJS entry (index.js around line 116) and the ESM entry (src/esm/index.js around line 114) append an approximately 123 KB top-level obfuscated block after a copy of the legitimate base-x source. The block installs a VM-style dispatcher on globalThis (registries named vmr_3f4688 and vmw_bf472f), manipulates Object.defineProperty and __proto__, and contains multiple fetch references, so a network-capable code path is wired up and runs unconditionally when a consumer requires or imports the package. A base-encoding library has no functional need for a large globalThis-poisoning obfuscated VM with network fetch at module top level; the payload is duplicated across both module systems so it fires for CJS and ESM consumers alike. ## Source: ghsa-malware (4891fcf0d0e6192d9be14faf68411bd475129a1245b5c863a9daaa6f66e66166) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Affected software

npmghsa
base65-12x
Affected versions
=5.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 00:59:47 UTC

Technical Analysis

The base65-12x npm package is a typosquatting malicious package that reuses the legitimate base-x repository homepage to appear legitimate. Both its CommonJS and ESM entry points include a roughly 123 KB obfuscated payload that sets up a VM-style dispatcher on the globalThis object, alters Object.defineProperty and __proto__, and includes multiple network fetch calls. This payload executes unconditionally when the package is imported or required, enabling remote code execution and persistent compromise. The package's functionality as a base-encoding library does not justify this behavior, confirming its malicious nature. Systems with this package installed are at high risk of full compromise.

Potential Impact

Systems that have installed or are running the base65-12x package are considered fully compromised. The malicious payload grants an attacker extensive control over the affected system, potentially exposing all stored secrets and keys. Because the malicious code runs immediately upon module import, it can execute arbitrary code and perform network operations without user consent. Even after removal of the package, the system may remain compromised due to persistent malware installed by the payload.

Mitigation Recommendations

Immediate removal of the base65-12x package is recommended. All secrets, credentials, and keys stored on the affected system should be rotated from a separate, uncompromised device. Due to the high likelihood of full system compromise, a complete system rebuild or forensic investigation is advised to ensure all malicious artifacts are eradicated. There is no official patch or fix for this malicious package; prevention relies on avoiding installation and using trusted package sources.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13746
Osv Schema Version
1.7.4
Aliases
["GHSA-c4w7-m3hx-xx75"]
Ecosystems
["npm"]

Threat ID: 6a7bc14ebf8831d539b15639

Added to database: 08/12/2026, 00:41:50 UTC

Last enriched: 08/12/2026, 00:59:47 UTC

Last updated: 09/24/2026, 18:16:48 UTC

Views: 64

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses