Malicious code in bs58-77 (npm)
The npm package bs58-77 is a typosquatting package that does not contain malicious code itself but depends on a malicious package base65-77x. The base65-77x package exfiltrates sensitive data by sending decoded strings, often private keys or seeds, to a hardcoded command and control server. This behavior enables secret leakage when bs58-77 is installed in a project. The malicious packages were published in a coordinated campaign by a single maintainer account within a short time frame. The affected version is exactly 6.0.1.
AI Analysis
Technical Summary
bs58-77 is a typosquatting npm package mimicking the legitimate bs58 base58 codec. It re-exports functionality from a malicious dependency base65-77x, which is a near-copy of base-x but with a modified decode() function that exfiltrates all decoded strings via HTTP POST to a hardcoded IP address. Since base-x/bs58 libraries are used to decode private keys and seeds in crypto tooling, this results in the leakage of sensitive cryptographic secrets. The bs58-77 package and related wrappers were published in a matched campaign by one maintainer account on 2026-08-11. Installing bs58-77 version 6.0.1 is sufficient to introduce this exfiltration behavior.
Potential Impact
Installation of [email protected] causes runtime inclusion of the malicious base65-77x package, which exfiltrates all decoded strings to an attacker-controlled server. This leads to leakage of sensitive cryptographic secrets such as private keys and seeds, potentially compromising the security of affected systems or wallets that rely on this package for base58 decoding.
Mitigation Recommendations
No official patch or fix is currently documented. Users should avoid installing bs58-77 version 6.0.1 and remove it from any existing projects. Dependents should verify their dependency trees for the presence of bs58-77 or base65-77x and remove or replace them with legitimate packages. Monitor vendor advisories for any updates or official remediation guidance.
Malicious code in bs58-77 (npm)
Description
The npm package bs58-77 is a typosquatting package that does not contain malicious code itself but depends on a malicious package base65-77x. The base65-77x package exfiltrates sensitive data by sending decoded strings, often private keys or seeds, to a hardcoded command and control server. This behavior enables secret leakage when bs58-77 is installed in a project. The malicious packages were published in a coordinated campaign by a single maintainer account within a short time frame. The affected version is exactly 6.0.1.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
bs58-77 is a typosquatting npm package mimicking the legitimate bs58 base58 codec. It re-exports functionality from a malicious dependency base65-77x, which is a near-copy of base-x but with a modified decode() function that exfiltrates all decoded strings via HTTP POST to a hardcoded IP address. Since base-x/bs58 libraries are used to decode private keys and seeds in crypto tooling, this results in the leakage of sensitive cryptographic secrets. The bs58-77 package and related wrappers were published in a matched campaign by one maintainer account on 2026-08-11. Installing bs58-77 version 6.0.1 is sufficient to introduce this exfiltration behavior.
Potential Impact
Installation of [email protected] causes runtime inclusion of the malicious base65-77x package, which exfiltrates all decoded strings to an attacker-controlled server. This leads to leakage of sensitive cryptographic secrets such as private keys and seeds, potentially compromising the security of affected systems or wallets that rely on this package for base58 decoding.
Mitigation Recommendations
No official patch or fix is currently documented. Users should avoid installing bs58-77 version 6.0.1 and remove it from any existing projects. Dependents should verify their dependency trees for the presence of bs58-77 or base65-77x and remove or replace them with legitimate packages. Monitor vendor advisories for any updates or official remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14018
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a7f43f1bf8831d5395d7671
Added to database: 08/14/2026, 16:36:01 UTC
Last enriched: 08/14/2026, 16:48:05 UTC
Last updated: 09/25/2026, 19:56:35 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.