base65-33x @5.0.2
Vulnerability report · Last retrieved from osv.dev August 12, 2026 at 3:23 AM UTC
OSV ID
MAL-2026-13749
Ecosystem
npm
Summary
Package name resembles the popular base-x encoder/decoder. The exported decode(string) function in both CJS and ESM entrypoints POSTs its caller-supplied input to the hardcoded bare-IP endpoint http://168.231.81.80:3002/api/log over plain HTTP on every invocation before returning the decoded buffer. Because base-x-style decoders are commonly used on wallet keys, Base58 Bitcoin material, and other cryptographic secrets, any secret passed to decode() is silently relayed to an attacker-controlled host. Both require and import consumers trigger the same relay path.
Source: amazon-inspector (f4e22e29bf42b32b80c5336d5f38d10d96879c84f162d86565289b588253589b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.