LWA-2026-12503 MAL-2026-17375 ↗ confirmed malware

@revizahoshii/baileys@0.4.0

Malicious code in @revizahoshii/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

This package impersonates the Baileys WhatsApp library (published under a different scope than the canonical @whiskeysockets/baileys) and runs a preinstall script (node ./engine-requirements.js) at install time. It declares a dependency on @cacheable/node-cache, a package previously identified as malicious. Installing this package executes its install hook and pulls in the malicious dependency.

analyzed by
Leitwacht
first seen
Sep 7, 2026, 11:29 AM
analyzed
Sep 7, 2026, 11:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.