LWA-2026-12296 confirmed malware

lynxog@4.0.0

Malicious code in lynxog (npm)

T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or InformationT1059.007 · JavaScript

Analysis

The package's main entry point (main.js) is a heavily obfuscated JavaScript payload, alongside a second 1.1MB obfuscated file (Levvi.js). It declares a dependency on the WhatsApp library @whiskeysockets/baileys but aliases it to npm:levvleys, so installing the package pulls in an attacker-controlled substitute for the real library that the bundled bot code imports. A functional WhatsApp bot module (lynx/index.mjs) is shipped alongside the obfuscated payloads.

analyzed by
Leitwacht
first seen
Sep 21, 2026, 08:53 AM
analyzed
Sep 21, 2026, 08:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.