LWA-2026-11534 confirmed malware

asistenyorstore@8.0.14

Malicious code in asistenyorstore (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

asistenyorstore is a republished clone of the WhiskeySockets/Baileys WhatsApp automation library that installs and invokes known-malicious dependencies in its core crypto and authentication paths. Its dependency tree includes @cacheable/node-cache, @skycodee/libsignal, and cache-manager, which are used for signal encryption (lib/Signal/libsignal.js), auth-state caching (lib/Utils/auth-utils.js, lib/Socket/messages-send.js, lib/Socket/messages-recv.js), and the cache-manager store (lib/Store/make-cache-manager-store.js). Installing this package pulls these malicious packages into the dependency tree and executes them during normal library operation.

analyzed by
Leitwacht
first seen
Aug 20, 2026, 09:55 PM
analyzed
Aug 20, 2026, 09:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.