@bottino/baileys@1.0.1
Malicious code in @bottino/baileys (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
@bottino/baileys is a combosquat of the baileys WhatsApp API library (canonical @whiskeysockets/baileys). Its preinstall hook only checks the Node.js version, but the package's runtime code (lib/Socket/messages-send.js, messages-recv.js, chats.js, index.js, lib/Utils/auth-utils.js) imports the dependency @cacheable/node-cache, which is a known-malware package. Installing this package pulls the compromised dependency into the dependency tree and executes it at runtime.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 04:11 PM
- analyzed
- Aug 10, 2026, 04:12 PM
Related advisories
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
- utils-style-engine@10.2.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.