@sahril2nd/baileys@1.0.21
Malicious code in @sahril2nd/baileys (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
A fork of the Baileys WhatsApp library published under a different scope (@sahril2nd/baileys) that declares dependencies on packages previously identified as malicious: cache-manager@4.0.1 and @cacheable/node-cache@^1.4.0. Installing this package pulls in those known-malicious dependencies as part of its dependency tree. The package also ships a preinstall hook (engine-requirements.js) that only checks the Node.js version, and its own source is a modified Baileys fork with added WhatsApp Business features.
- analyzed by
- Leitwacht
- first seen
- Aug 30, 2026, 08:49 AM
- analyzed
- Aug 30, 2026, 08:49 AM
Related advisories
- autobahn-electron-probe@99.99.1
- discord-mfa-solver@1.0.2
- mfaatest@1.0.0
- helmify@0.0.1
- night-casino@1.0.0
- simsino-casino@1.0.0
- bdmbet-online@1.0.0
- lunubet-casino@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.