LWA-2026-11701 confirmed malware
@berrysdk/transport@0.1.9
Malicious code in @berrysdk/transport (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
A trojanized clone of the Baileys WhatsApp Web library. The package vendors a copy of the Baileys source tree but replaces the legitimate node-cache dependency with the malicious scoped package @cacheable/node-cache, rewriting every vendored import (messages-send.js, messages-recv.js, chats.js, identity-change-handler.js, auth-utils.js) to load it. Installing this package pulls in the malicious dependency at install time, executing its payload as part of the dependency tree.
- analyzed by
- Leitwacht
- first seen
- Aug 28, 2026, 11:43 PM
- analyzed
- Aug 28, 2026, 11:43 PM
Related advisories
- modules-newline@0.0.6
- @guildai-services/guildai@99.9.1
- bs58-33@6.0.1
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.