@versacode/baileys@1.4.5-beta.1
Malicious code in @versacode/baileys (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
A combosquat of the @whiskeysockets/baileys WhatsApp Web API published under the @versacode scope. The package installs a known-malicious dependency (@cacheable/node-cache) and pulls the libsignal dependency from a foreign scope (@queenanya/libsignal) via a direct registry URL rather than the canonical package, so installing it pulls the malicious dependency chain into the project. The libsignal module is imported and exercised at runtime for WhatsApp E2EE session handling.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 06:22 PM
- analyzed
- Sep 5, 2026, 06:23 PM
Related advisories
- @berrysdk/transport@0.1.9
- modules-newline@0.0.6
- @guildai-services/guildai@99.9.1
- bs58-33@6.0.1
- @bottino/baileys@1.0.1
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.