LWA-2026-11812 confirmed malware

@kentsuki/baileys@1.0.0

Malicious code in @kentsuki/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1078 · Valid Accounts

Analysis

Combosquat of the @whiskeysockets/baileys WhatsApp library. When a victim connects a WhatsApp session, the package silently fetches a channel list from hxxps://raw[.]githubusercontent[.]com/DGXeon13/strings/refs/heads/main/strings[.]json and follows every channel in that list on the victim's authenticated WhatsApp account (one follow every 11 seconds, starting 120 seconds after connection), boosting attacker-controlled newsletter channels. It also performs a remote version check against hxxps://raw[.]githubusercontent[.]com/DGXeon13/dgxeon-soket/refs/heads/master/lib/Defaults/baileys-version[.]json and redirects the libsignal dependency to the attacker's fork npm:@dgxeon13/libsignal-node@1.0.0. Default rich-menu CTA links point to t[.]me/kenzki_01.

analyzed by
Leitwacht
first seen
Sep 1, 2026, 05:55 AM
analyzed
Sep 1, 2026, 05:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.