LWA-2026-11701 confirmed malware

@berrysdk/transport@0.1.9

Malicious code in @berrysdk/transport (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

A trojanized clone of the Baileys WhatsApp Web library. The package vendors a copy of the Baileys source tree but replaces the legitimate node-cache dependency with the malicious scoped package @cacheable/node-cache, rewriting every vendored import (messages-send.js, messages-recv.js, chats.js, identity-change-handler.js, auth-utils.js) to load it. Installing this package pulls in the malicious dependency at install time, executing its payload as part of the dependency tree.

analyzed by
Leitwacht
first seen
Aug 28, 2026, 11:43 PM
analyzed
Aug 28, 2026, 11:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.