LWA-2026-12220 MAL-2026-16276 ↗ confirmed malware

@lekzo/baileys@0.0.1

Malicious code in @lekzo/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

@lekzo/baileys@0.0.1 is a combosquat clone of the @whiskeysockets/baileys WhatsApp library, published under the @lekzo scope. The package bundles a near-verbatim copy of the real Baileys source tree but declares runtime dependencies on @cacheable/node-cache and cache-manager, both of which are known-malicious packages, so installing this package pulls the malicious dependency chain into the installer's dependency tree. The package name reuses the canonical "baileys" brand under a different scope to deceive installers into treating it as the legitimate library.

analyzed by
Leitwacht
first seen
Sep 15, 2026, 07:24 AM
analyzed
Sep 15, 2026, 07:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.