LWA-2026-11906 MAL-2026-16068 ↗ confirmed malware

@versacode/baileys@1.4.5-beta.1

Malicious code in @versacode/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

A combosquat of the @whiskeysockets/baileys WhatsApp Web API published under the @versacode scope. The package installs a known-malicious dependency (@cacheable/node-cache) and pulls the libsignal dependency from a foreign scope (@queenanya/libsignal) via a direct registry URL rather than the canonical package, so installing it pulls the malicious dependency chain into the project. The libsignal module is imported and exercised at runtime for WhatsApp E2EE session handling.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 06:22 PM
analyzed
Sep 5, 2026, 06:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.