LWA-2026-1268 confirmed malware

alice-baileys@2.0.1

Malicious code in alice-baileys (npm)

Analysis

Trojanized WhatsApp Baileys fork: alice-baileys@2.0.1 carries a remote phone-home gate. Base64-obfuscated URLs decode at runtime to fetch a GitHub token from pastebin[.]com/raw/wh34RDBe, which is then used to read an allowlist JSON from api[.]github[.]com/repos/xyroorynzz/Alice/contents/Alicev2.json. The user's WhatsApp phone number is hashed (sha256 of md5) and checked against the remote allowlist in requestPairingCodes (socket.js:389). The preinstall script only performs a Node >=20 check. The Pastebin-sourced token is attacker-controlled, making the fetched value a dynamic remote-code surface.

analyzed by
Leitwacht
first seen
May 29, 2026, 10:56 PM
analyzed
May 29, 2026, 10:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.