asistenyorstore@8.0.14
Malicious code in asistenyorstore (npm)
Analysis
asistenyorstore is a republished clone of the WhiskeySockets/Baileys WhatsApp automation library that installs and invokes known-malicious dependencies in its core crypto and authentication paths. Its dependency tree includes @cacheable/node-cache, @skycodee/libsignal, and cache-manager, which are used for signal encryption (lib/Signal/libsignal.js), auth-state caching (lib/Utils/auth-utils.js, lib/Socket/messages-send.js, lib/Socket/messages-recv.js), and the cache-manager store (lib/Store/make-cache-manager-store.js). Installing this package pulls these malicious packages into the dependency tree and executes them during normal library operation.
- analyzed by
- Leitwacht
- first seen
- Aug 20, 2026, 09:55 PM
- analyzed
- Aug 20, 2026, 09:55 PM
Related advisories
- express-session-handler@2.3.3
- chai-as-soul@2.3.6
- @httttt/mcp-npx-fetch-1@1.0.0
- heheheshsds@2.0.0
- @wizloft/harness@0.1.1-alpha.3
- dev-env-check@1.0.3
- plugin-react-vite@2.1.2
- chai-as-gateway@7.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.