Malicious code in bs58-15 (npm)
The npm package bs58-15 is a typosquatting package impersonating the popular bs58 base58 codec. It contains no malicious code itself but depends on base65-15x, a malicious package that exfiltrates decoded strings by sending them to a hardcoded command-and-control server. This behavior risks leaking sensitive cryptographic secrets such as private keys and seeds. The bs58-15 package and related siblings were published in a coordinated campaign by a single maintainer account. Installing bs58-15 introduces this exfiltration behavior into dependent projects.
AI Analysis
Technical Summary
bs58-15 is a malicious npm typosquat of the legitimate bs58 package. Its main module requires and re-exports the base65-15x package, which is a near-verbatim clone of the legitimate base-x package but with a malicious decode() function. This decode() function exfiltrates every string passed to it by POSTing the raw input to a hardcoded IP address (http://46.250.253.63:3000/api/log) before throwing an error. Because base-x/bs58 are used in crypto tooling to decode private keys and seeds, this results in frequent exfiltration of sensitive secrets. The bs58-15 package and its siblings (bs58-33, bs58-77) were published within a short timeframe by the same npm maintainer account, forming a matched delivery and exfiltration campaign. Any project installing bs58-15 will execute the malicious code at import time due to the immediate invocation of the malicious dependency.
Potential Impact
The malicious base65-15x dependency exfiltrates sensitive data such as private keys and seeds used in cryptographic operations by sending them to an attacker-controlled server. This compromises the confidentiality of secrets in any project that installs and uses bs58-15, potentially leading to unauthorized access or theft of cryptographic assets. The attack is triggered at runtime when the package is imported, making it a direct risk to dependent projects.
Mitigation Recommendations
No official patch or fix is currently available. Users and developers should avoid installing or using the bs58-15 package and its siblings (bs58-33, bs58-77). Audit dependencies carefully to ensure no typosquatting or malicious packages are included. Remove bs58-15 and any related malicious packages from projects and dependency trees immediately. Monitor for updates from npm or the legitimate bs58 package maintainers for any official advisories or remediation.
Malicious code in bs58-15 (npm)
Description
The npm package bs58-15 is a typosquatting package impersonating the popular bs58 base58 codec. It contains no malicious code itself but depends on base65-15x, a malicious package that exfiltrates decoded strings by sending them to a hardcoded command-and-control server. This behavior risks leaking sensitive cryptographic secrets such as private keys and seeds. The bs58-15 package and related siblings were published in a coordinated campaign by a single maintainer account. Installing bs58-15 introduces this exfiltration behavior into dependent projects.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
bs58-15 is a malicious npm typosquat of the legitimate bs58 package. Its main module requires and re-exports the base65-15x package, which is a near-verbatim clone of the legitimate base-x package but with a malicious decode() function. This decode() function exfiltrates every string passed to it by POSTing the raw input to a hardcoded IP address (http://46.250.253.63:3000/api/log) before throwing an error. Because base-x/bs58 are used in crypto tooling to decode private keys and seeds, this results in frequent exfiltration of sensitive secrets. The bs58-15 package and its siblings (bs58-33, bs58-77) were published within a short timeframe by the same npm maintainer account, forming a matched delivery and exfiltration campaign. Any project installing bs58-15 will execute the malicious code at import time due to the immediate invocation of the malicious dependency.
Potential Impact
The malicious base65-15x dependency exfiltrates sensitive data such as private keys and seeds used in cryptographic operations by sending them to an attacker-controlled server. This compromises the confidentiality of secrets in any project that installs and uses bs58-15, potentially leading to unauthorized access or theft of cryptographic assets. The attack is triggered at runtime when the package is imported, making it a direct risk to dependent projects.
Mitigation Recommendations
No official patch or fix is currently available. Users and developers should avoid installing or using the bs58-15 package and its siblings (bs58-33, bs58-77). Audit dependencies carefully to ensure no typosquatting or malicious packages are included. Remove bs58-15 and any related malicious packages from projects and dependency trees immediately. Monitor for updates from npm or the legitimate bs58 package maintainers for any official advisories or remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13964
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7f440cbf8831d5395fb7ee
Added to database: 08/14/2026, 16:36:28 UTC
Last enriched: 08/14/2026, 16:59:18 UTC
Last updated: 08/14/2026, 22:10:29 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.