Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in bs58-15 (npm)

0
High
Published: 08/13/2026 (08/13/2026, 00:00:00 UTC)
Source: GCVE Database
Product: bs58-15

Description

The npm package bs58-15 is a typosquatting package impersonating the popular bs58 base58 codec. It contains no malicious code itself but depends on base65-15x, a malicious package that exfiltrates decoded strings by sending them to a hardcoded command-and-control server. This behavior risks leaking sensitive cryptographic secrets such as private keys and seeds. The bs58-15 package and related siblings were published in a coordinated campaign by a single maintainer account. Installing bs58-15 introduces this exfiltration behavior into dependent projects.

Affected software

npmghsa
bs58-15
Affected versions
=6.0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 16:59:18 UTC

Technical Analysis

bs58-15 is a malicious npm typosquat of the legitimate bs58 package. Its main module requires and re-exports the base65-15x package, which is a near-verbatim clone of the legitimate base-x package but with a malicious decode() function. This decode() function exfiltrates every string passed to it by POSTing the raw input to a hardcoded IP address (http://46.250.253.63:3000/api/log) before throwing an error. Because base-x/bs58 are used in crypto tooling to decode private keys and seeds, this results in frequent exfiltration of sensitive secrets. The bs58-15 package and its siblings (bs58-33, bs58-77) were published within a short timeframe by the same npm maintainer account, forming a matched delivery and exfiltration campaign. Any project installing bs58-15 will execute the malicious code at import time due to the immediate invocation of the malicious dependency.

Potential Impact

The malicious base65-15x dependency exfiltrates sensitive data such as private keys and seeds used in cryptographic operations by sending them to an attacker-controlled server. This compromises the confidentiality of secrets in any project that installs and uses bs58-15, potentially leading to unauthorized access or theft of cryptographic assets. The attack is triggered at runtime when the package is imported, making it a direct risk to dependent projects.

Mitigation Recommendations

No official patch or fix is currently available. Users and developers should avoid installing or using the bs58-15 package and its siblings (bs58-33, bs58-77). Audit dependencies carefully to ensure no typosquatting or malicious packages are included. Remove bs58-15 and any related malicious packages from projects and dependency trees immediately. Monitor for updates from npm or the legitimate bs58 package maintainers for any official advisories or remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13964
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7f440cbf8831d5395fb7ee

Added to database: 08/14/2026, 16:36:28 UTC

Last enriched: 08/14/2026, 16:59:18 UTC

Last updated: 08/14/2026, 22:10:29 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses