@revizahoshii/baileys@0.4.0
Malicious code in @revizahoshii/baileys (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
This package impersonates the Baileys WhatsApp library (published under a different scope than the canonical @whiskeysockets/baileys) and runs a preinstall script (node ./engine-requirements.js) at install time. It declares a dependency on @cacheable/node-cache, a package previously identified as malicious. Installing this package executes its install hook and pulls in the malicious dependency.
- analyzed by
- Leitwacht
- first seen
- Sep 7, 2026, 11:29 AM
- analyzed
- Sep 7, 2026, 11:30 AM
Related advisories
- bmc-i18n-extract-cli@1.1.1
- jwt-logger@2.1.9
- array-scala@1.2.5
- @versacode/baileys@1.4.5-beta.1
- dazaar-guild@1.0.0
- tailwindcss-ratio-styles@0.3.2
- ulid-intel@2.12.3
- thepokies-review@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.