LWA-2026-11320 confirmed malware
@mrzkyzdnii/baileys@0.3.18-mrzkyzdnii.2
Malicious code in @mrzkyzdnii/baileys (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
A fork of the Baileys WhatsApp automation library published under a different scope (@mrzkyzdnii/baileys) that depends on the known-malicious npm package @cacheable/node-cache, which is imported by five of the library's modules (lib/Socket/messages-send.js, lib/Socket/messages-recv.js, lib/Socket/chats.js, lib/Utils/identity-change-handler.js, lib/Utils/auth-utils.js). Installing this package pulls in the malicious dependency. The package's own preinstall hook only checks the Node.js version (>=20) and performs no additional payload.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 09:12 AM
- analyzed
- Aug 15, 2026, 09:13 AM
Related advisories
- tailwind-utility-kit@1.3.2
- postcss-initialize-provider@3.0.4
- mutex-thread@1.3.0
- tailwind-plugin-kit@1.3.2
- tailwind-toolkit@1.3.2
- @cdnshell/loader@0.0.1
- bootstrap-custom-ui@5.7.2
- datetime-fmt-xutil@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.