LWA-2026-12657 MAL-2026-17620 ↗ confirmed malware

dzyclutch-baileys@1.1.16

Malicious code in dzyclutch-baileys (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.007 · JavaScript

Analysis

dzyclutch-baileys is a repackaged fork of the WhatsApp Web API library "baileys" (combosquat: the real name appears intact behind a "dzyclutch-" prefix) that adds an install-time execution path. Its package.json declares a preinstall lifecycle hook, `node ./engine-requirements.js`, which runs automatically on `npm install` before any application code executes; the upstream library has no such hook. The package also redirects its `libsignal` dependency to a publisher-controlled package, `dzyclutch-libsignal-node`, instead of the upstream `libsignal-node`, so installation pulls code from the same untrusted source rather than the registry's canonical package. The manifest is machine-generated (the `keywords` field is a stringified array), consistent with scripted republishing. The published tarball is no longer retrievable from the registry, so the contents of `engine-requirements.js` and of `dzyclutch-libsignal-node` could not be read; the install-time hook and the substituted dependency are the concrete artifacts observable in the manifest. No network indicator (C2 host, IP, or URL) is present in the metadata, and none is claimed.

analyzed by
Leitwacht
first seen
Oct 3, 2026, 06:18 PM
analyzed
Oct 8, 2026, 11:11 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.