LWA-2026-12666 confirmed malware

@yaszz/bail@1.0.0

Malicious code in @yaszz/bail (npm)

T1195.002 · Compromise Software Supply ChainT1071.001 · Web ProtocolsT1102 · Web Service

Analysis

@yaszz/bail@1.0.0 is a republished fork of the Baileys WhatsApp WebSocket library with a hidden remote-tasking payload injected into lib/Utils/messages-media.js. The file defines an exported function loadBase(n, q) that decodes a base64 string into the URL hxxps://raw[.]githubusercontent[.]com/Yaszz-17/Newsletter/main/id[.]json, waits 80 seconds after the socket is created, then fetches that URL (with a cache-busting ?t=<timestamp> query) and parses the returned JSON as a list of newsletter IDs. For every entry it calls the caller-supplied newsletter-follow routine (n(i.id, q.FOLLOW)) with a 5-second delay between calls, so the package silently subscribes the victim's WhatsApp account to an attacker-controlled list of channels. The URL is base64-encoded and the whole routine is wrapped in empty catch blocks so it produces no logs or errors. The hook is wired in from lib/Socket/newsletter.js, which imports loadBase and invokes it at module load with the socket's newsletter query function, meaning the behaviour runs automatically for any application that imports the package — no user action required. The package also ships editor-backup sidecars (lib/Defaults/index.js.bak, lib/Socket/Client/websocket.js.bak, lib/Types/Newsletter.js.bak) alongside the live modules, and lib/index.js prints promotional Telegram/YouTube branding for the fork. The remote JSON file is publisher-controlled and can be changed at any time to alter which channels are followed, making it a live command channel rather than a static list.

analyzed by
Leitwacht
first seen
Oct 6, 2026, 08:09 PM
analyzed
Oct 8, 2026, 11:32 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.