LWA-2026-11660 confirmed malware
shadowmd@8.6.87
Malicious code in shadowmd (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
shadowmd@8.6.87 is a WhatsApp/Baileys fork that depends on libsignal: npm:@shadowmd/libsignal-node. That dependency ships an install.js which patches the bundled Baileys newsletter module and injects a delayed (120s) routine that uses the victim's authenticated WhatsApp session to follow an attacker-controlled newsletter channel (120363407277177688@newsletter). Installing the package silently enrolls the victim's WhatsApp account into following the attacker's channel.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 10:11 AM
- analyzed
- Aug 27, 2026, 10:12 AM
Related advisories
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
- tailwindcss-form-styles@0.5.15
- tailwindcss-3d-animate@1.2.2
- htps-provider@1.0.11
- @flagship-io/openfeature-provider-js@1.0.0
- date-fns-sync@1.0.0
- supersignaturenature@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.