LWA-2026-12501 MAL-2026-17351 ↗ confirmed malware

@bottino/baileys@1.0.1

Malicious code in @bottino/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

@bottino/baileys is a combosquat of the baileys WhatsApp API library (canonical @whiskeysockets/baileys). Its preinstall hook only checks the Node.js version, but the package's runtime code (lib/Socket/messages-send.js, messages-recv.js, chats.js, index.js, lib/Utils/auth-utils.js) imports the dependency @cacheable/node-cache, which is a known-malware package. Installing this package pulls the compromised dependency into the dependency tree and executes it at runtime.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 04:11 PM
analyzed
Aug 10, 2026, 04:12 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.