dzyclutch-baileys@1.1.21
Malicious code in dzyclutch-baileys (npm)
Analysis
dzyclutch-baileys is a combosquat on the baileys WhatsApp Web API library: it ships a cloned copy of the baileys source tree (same dependency set, same "Advanced WhatsApp Web API Library" description, same lib/ layout) under a prefixed name, with an install-time payload added. Its package.json declares a preinstall hook, "node ./engine-requirements.js", which executes a bundled script as soon as the package is installed — before any application code runs. The dependency tree is also tampered with: the core libsignal dependency is aliased to a same-publisher package ("libsignal": "npm:dzyclutch-libsignal-node"), pulling attacker-controlled code into the installer's dependency graph. The package also depends on packages previously used in malicious publishes (@cacheable/node-cache, cache-manager). Eleven versions were published in a burst. The published tarballs are no longer retrievable from the registry, so the contents of engine-requirements.js and the aliased libsignal package could not be read; no network endpoint, dropped-file path or credential target can be stated for this version. Installers of any dzyclutch-baileys or @diezyclutch/baileys version should treat the host as potentially compromised and rotate npm and repository credentials.
- analyzed by
- Leitwacht
- first seen
- Oct 3, 2026, 10:03 PM
- analyzed
- Oct 8, 2026, 11:11 AM
Related advisories
- dzyclutch-baileys@1.1.16 same package
- cwao@0.5.6
- random-certs@0.0.1
- css-reading-display-polyfill@1.0.0
- @subql/common@5.8.3
- botmaker-cli@0.1.19
- checkmate-remediation-assistant@1.0.0
- selfsigned-generator@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.