@fyxzpediaa/baileys@8.0.15
Malicious code in @fyxzpediaa/baileys (npm)
Analysis
@fyxzpediaa/baileys is a trojanized clone of the legitimate @whiskeysockets/baileys WhatsApp WebSocket library. On socket connect, injected code in lib/Socket/socket.js decodes an obfuscated URL and fetches a remote JSON list of WhatsApp newsletter IDs from hxxps://raw[.]githubusercontent[.]com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push[.]json. After a 200-second delay it sends w:mex newsletter-follow queries (query_id 7871414976211147) to @s[.]whatsapp[.]net for each ID, forcing the victim's WhatsApp account to subscribe to attacker-controlled newsletters. A second injected function decodes a hardcoded newsletter JID (120363302042233203@newsletter) via XOR/base64 and follows it as well. The payloads are hidden with char-code-array and XOR/base64 obfuscation.
- analyzed by
- Leitwacht
- first seen
- Aug 22, 2026, 07:15 AM
- analyzed
- Aug 22, 2026, 07:21 AM
Related advisories
- hatdhat-testkit@3.2.14
- solidity-testing-utils@1.2.0
- rust-testing-utils@2.3.0
- internallib_v902@1.2.1
- kelly-sizing@0.1.0
- @next-fonts/font@1.0.1
- mcq-session@1.0.4
- @pablo_clueless/sniffr@0.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.