LWA-2026-11971 MAL-2026-16105 ↗ confirmed malware

@sahril2nd/baileys@1.0.21

Malicious code in @sahril2nd/baileys (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

A fork of the Baileys WhatsApp library published under a different scope (@sahril2nd/baileys) that declares dependencies on packages previously identified as malicious: cache-manager@4.0.1 and @cacheable/node-cache@^1.4.0. Installing this package pulls in those known-malicious dependencies as part of its dependency tree. The package also ships a preinstall hook (engine-requirements.js) that only checks the Node.js version, and its own source is a modified Baileys fork with added WhatsApp Business features.

analyzed by
Leitwacht
first seen
Aug 30, 2026, 08:49 AM
analyzed
Aug 30, 2026, 08:49 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.