Malicious code in @tabrex/bs58 (npm)
The @tabrex/bs58 npm package version 6.0.3 is a malicious typosquatting package impersonating the legitimate cryptocoinjs/bs58 package. It contains heavily obfuscated code that, upon import or require, respawns the Node.js process detached, downloads an encrypted binary over HTTPS, verifies and decrypts it, then executes it on the developer or build machine. This results in execution of attacker-controlled code during module load time, representing a supply-chain attack.
AI Analysis
Technical Summary
@tabrex/bs58 version 6.0.3 mimics the legitimate bs58 package by copying its README, API, and repository URL but embeds a heavily obfuscated payload in its entrypoints. The payload uses RC4-based string decoding, control-flow flattening, and anti-debugging techniques. When the package is loaded, it respawns the Node.js process with a sentinel environment variable, downloads an encrypted binary, verifies its SHA256 hash, decrypts it using AES-256-GCM with a key derived from XORing base64 fragments, sets execution permissions, and runs the binary. This causes arbitrary attacker-controlled code execution on any system that installs and loads this package, making it a clear supply-chain compromise via typosquatting.
Potential Impact
Any project that installs and requires or imports @tabrex/bs58 version 6.0.3 will execute attacker-controlled code on the developer or build machine. This can lead to full compromise of the environment where the package is used, including potential data theft, system manipulation, or further malware deployment. The attack occurs silently at module load time, increasing risk of unnoticed compromise.
Mitigation Recommendations
No official patch or fix is currently available for @tabrex/bs58 version 6.0.3. Users should immediately remove this package from their dependencies and replace it with the legitimate bs58 package from the official cryptocoinjs repository. Avoid installing packages with names similar to popular libraries without verifying authenticity. Monitor dependency trees for typosquatting packages and use trusted sources only.
Malicious code in @tabrex/bs58 (npm)
Description
The @tabrex/bs58 npm package version 6.0.3 is a malicious typosquatting package impersonating the legitimate cryptocoinjs/bs58 package. It contains heavily obfuscated code that, upon import or require, respawns the Node.js process detached, downloads an encrypted binary over HTTPS, verifies and decrypts it, then executes it on the developer or build machine. This results in execution of attacker-controlled code during module load time, representing a supply-chain attack.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
@tabrex/bs58 version 6.0.3 mimics the legitimate bs58 package by copying its README, API, and repository URL but embeds a heavily obfuscated payload in its entrypoints. The payload uses RC4-based string decoding, control-flow flattening, and anti-debugging techniques. When the package is loaded, it respawns the Node.js process with a sentinel environment variable, downloads an encrypted binary, verifies its SHA256 hash, decrypts it using AES-256-GCM with a key derived from XORing base64 fragments, sets execution permissions, and runs the binary. This causes arbitrary attacker-controlled code execution on any system that installs and loads this package, making it a clear supply-chain compromise via typosquatting.
Potential Impact
Any project that installs and requires or imports @tabrex/bs58 version 6.0.3 will execute attacker-controlled code on the developer or build machine. This can lead to full compromise of the environment where the package is used, including potential data theft, system manipulation, or further malware deployment. The attack occurs silently at module load time, increasing risk of unnoticed compromise.
Mitigation Recommendations
No official patch or fix is currently available for @tabrex/bs58 version 6.0.3. Users should immediately remove this package from their dependencies and replace it with the legitimate bs58 package from the official cryptocoinjs repository. Avoid installing packages with names similar to popular libraries without verifying authenticity. Monitor dependency trees for typosquatting packages and use trusted sources only.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10523
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff6868715ace432f1cf4
Added to database: 07/14/2026, 09:20:40 UTC
Last enriched: 07/14/2026, 09:34:39 UTC
Last updated: 07/28/2026, 05:09:25 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.