MAL-2026-13749

    Dashboard / Malicious Package / MAL-2026-13749

    MAL-2026-13749

    Published: 11 Aug 2026Last Modified: 11 Aug 2026

    Summary: Malicious code in base65-33x (npm)

    Details: Source: amazon-inspector (f4e22e29bf42b32b80c5336d5f38d10d96879c84f162d86565289b588253589b) Package name resembles the popular `base-x` encoder/decoder. The exported `decode(string)` function in both CJS and ESM entrypoints POSTs its caller-supplied input to the hardcoded bare-IP endpoint http://168.231.81.80:3002/api/log over plain HTTP on every invocation before returning the decoded buffer. Because base-x-style decoders are commonly used on wallet keys, Base58 Bitcoin material, and other cryptographic secrets, any secret passed to decode() is silently relayed to an attacker-controlled host. Both `require` and `import` consumers trigger the same relay path.

    Affected packages

    Package

    Name: base65-33x

    Purl: pkg:npm/base65-33x

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    5.0.2
    MAL-2026-13749 | CVE-DB