MAL-2026-14018

    Dashboard / Malicious Package / MAL-2026-14018

    MAL-2026-14018

    Published: 13 Aug 2026Last Modified: 14 Aug 2026

    Summary: Malicious code in bs58-77 (npm)

    Details: npm/bs58-77 is a typosquat of the popular bs58 base58 codec (cryptocoinjs). The package contains no malicious code of its own: its src/cjs/index.cjs simply does require("base65-77x") and re-exports it. Its sole purpose is to pull in the malicious sink package base65-77x as a runtime dependency (declared dependency: base65-77x: ^5.0.1). base65-77x is a near-verbatim clone of base-x whose decode() exfiltrates every string passed to it by POSTing the raw input to a hardcoded bare-IP C2 (http://46.250.253.63:3000/api/log) before throwing; because base-x/bs58 are how crypto tooling base58-decodes private keys and seeds, the exfiltrated values are frequently secrets. The sink is reported separately as MAL-2026-13750. bs58-77 and its sibling wrappers (bs58-15, bs58-33) were published alongside the three base65 sinks by a single npm maintainer account (smallmantis) within a ~90-minute window on 2026-08-11, forming a matched six-package delivery-plus-exfiltration campaign. Installing bs58-77 is sufficient to introduce the key-exfiltration behavior into a dependent project. Source: amazon-inspector (b115b88f23da3c8c4256b2d15d8766695ddadde12e884e1c36c36440b4652ba7) The package was found to contain malicious code or consuming dependency that contains malicious code

    Affected packages

    Package

    Name: bs58-77

    Purl: pkg:npm/bs58-77

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    6.0.1