@lekzo/baileys@0.0.1
Malicious code in @lekzo/baileys (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
@lekzo/baileys@0.0.1 is a combosquat clone of the @whiskeysockets/baileys WhatsApp library, published under the @lekzo scope. The package bundles a near-verbatim copy of the real Baileys source tree but declares runtime dependencies on @cacheable/node-cache and cache-manager, both of which are known-malicious packages, so installing this package pulls the malicious dependency chain into the installer's dependency tree. The package name reuses the canonical "baileys" brand under a different scope to deceive installers into treating it as the legitimate library.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 07:24 AM
- analyzed
- Sep 15, 2026, 07:26 AM
Related advisories
- bx-ui-view@1.0.0
- @versacode/baileys@1.4.5-beta.1
- @berrysdk/transport@0.1.9
- modules-newline@0.0.6
- @guildai-services/guildai@99.9.1
- bs58-33@6.0.1
- @bottino/baileys@1.0.1
- @morpho-blue-liquidation-bot/data-providers@2.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.