LWA-2026-11146 MAL-2026-13932 ↗ confirmed malware

my-auto-follow@1.0.0

Malicious code in my-auto-follow (npm)

T1195.002 · Compromise Software Supply ChainT1071 · Application Layer ProtocolT1105 · Ingress Tool Transfer

Analysis

my-auto-follow@1.0.0 is a WhatsApp Web (Baileys) library fork whose install/require triggers network egress and which depends on known-malicious cache packages (@cacheable/node-cache, cache-manager). The package pulls in these malicious dependencies and makes outbound network connections during installation/execution, behaviour consistent with a beacon/C2 channel. Installers should treat the package and its dependency chain as compromised.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 06:44 AM
analyzed
Aug 13, 2026, 06:46 AM
weekly installs
224

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.