my-auto-follow@1.0.0
Malicious code in my-auto-follow (npm)
T1195.002 · Compromise Software Supply ChainT1071 · Application Layer ProtocolT1105 · Ingress Tool Transfer
Analysis
my-auto-follow@1.0.0 is a WhatsApp Web (Baileys) library fork whose install/require triggers network egress and which depends on known-malicious cache packages (@cacheable/node-cache, cache-manager). The package pulls in these malicious dependencies and makes outbound network connections during installation/execution, behaviour consistent with a beacon/C2 channel. Installers should treat the package and its dependency chain as compromised.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 06:44 AM
- analyzed
- Aug 13, 2026, 06:46 AM
- weekly installs
- 224
Related advisories
- internallib_v756@1.0.7
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-map-kit@1.0.0
- dolyame-ui-noindex@35.8.1
- ded-pwa-c-boxy-di@35.2.2
- devplatform-spa-errors@35.5.7
- internallib_v514@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.