LWA-2026-11320 confirmed malware

@mrzkyzdnii/baileys@0.3.18-mrzkyzdnii.2

Malicious code in @mrzkyzdnii/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

A fork of the Baileys WhatsApp automation library published under a different scope (@mrzkyzdnii/baileys) that depends on the known-malicious npm package @cacheable/node-cache, which is imported by five of the library's modules (lib/Socket/messages-send.js, lib/Socket/messages-recv.js, lib/Socket/chats.js, lib/Utils/identity-change-handler.js, lib/Utils/auth-utils.js). Installing this package pulls in the malicious dependency. The package's own preinstall hook only checks the Node.js version (>=20) and performs no additional payload.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 09:12 AM
analyzed
Aug 15, 2026, 09:13 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.