Skip to main content

Malicious code in bs58-77 (npm)

0
High
Published: 08/13/2026 (08/13/2026, 00:00:00 UTC)
Source: GCVE Database
Product: bs58-77

Description

The npm package bs58-77 is a typosquatting package that does not contain malicious code itself but depends on a malicious package base65-77x. The base65-77x package exfiltrates sensitive data by sending decoded strings, often private keys or seeds, to a hardcoded command and control server. This behavior enables secret leakage when bs58-77 is installed in a project. The malicious packages were published in a coordinated campaign by a single maintainer account within a short time frame. The affected version is exactly 6.0.1.

Affected software

npmghsa
bs58-77
Affected versions
=6.0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 16:48:05 UTC

Technical Analysis

bs58-77 is a typosquatting npm package mimicking the legitimate bs58 base58 codec. It re-exports functionality from a malicious dependency base65-77x, which is a near-copy of base-x but with a modified decode() function that exfiltrates all decoded strings via HTTP POST to a hardcoded IP address. Since base-x/bs58 libraries are used to decode private keys and seeds in crypto tooling, this results in the leakage of sensitive cryptographic secrets. The bs58-77 package and related wrappers were published in a matched campaign by one maintainer account on 2026-08-11. Installing bs58-77 version 6.0.1 is sufficient to introduce this exfiltration behavior.

Potential Impact

Installation of [email protected] causes runtime inclusion of the malicious base65-77x package, which exfiltrates all decoded strings to an attacker-controlled server. This leads to leakage of sensitive cryptographic secrets such as private keys and seeds, potentially compromising the security of affected systems or wallets that rely on this package for base58 decoding.

Mitigation Recommendations

No official patch or fix is currently documented. Users should avoid installing bs58-77 version 6.0.1 and remove it from any existing projects. Dependents should verify their dependency trees for the presence of bs58-77 or base65-77x and remove or replace them with legitimate packages. Monitor vendor advisories for any updates or official remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14018
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a7f43f1bf8831d5395d7671

Added to database: 08/14/2026, 16:36:01 UTC

Last enriched: 08/14/2026, 16:48:05 UTC

Last updated: 09/25/2026, 19:56:35 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses