LWA-2026-11548 confirmed malware

@fyxzpediaa/baileys@8.0.15

Malicious code in @fyxzpediaa/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

@fyxzpediaa/baileys is a trojanized clone of the legitimate @whiskeysockets/baileys WhatsApp WebSocket library. On socket connect, injected code in lib/Socket/socket.js decodes an obfuscated URL and fetches a remote JSON list of WhatsApp newsletter IDs from hxxps://raw[.]githubusercontent[.]com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push[.]json. After a 200-second delay it sends w:mex newsletter-follow queries (query_id 7871414976211147) to @s[.]whatsapp[.]net for each ID, forcing the victim's WhatsApp account to subscribe to attacker-controlled newsletters. A second injected function decodes a hardcoded newsletter JID (120363302042233203@newsletter) via XOR/base64 and follows it as well. The payloads are hidden with char-code-array and XOR/base64 obfuscation.

analyzed by
Leitwacht
first seen
Aug 22, 2026, 07:15 AM
analyzed
Aug 22, 2026, 07:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.