alice-baileys@2.0.1
Malicious code in alice-baileys (npm)
Analysis
Trojanized WhatsApp Baileys fork: alice-baileys@2.0.1 carries a remote phone-home gate. Base64-obfuscated URLs decode at runtime to fetch a GitHub token from pastebin[.]com/raw/wh34RDBe, which is then used to read an allowlist JSON from api[.]github[.]com/repos/xyroorynzz/Alice/contents/Alicev2.json. The user's WhatsApp phone number is hashed (sha256 of md5) and checked against the remote allowlist in requestPairingCodes (socket.js:389). The preinstall script only performs a Node >=20 check. The Pastebin-sourced token is attacker-controlled, making the fetched value a dynamic remote-code surface.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 10:56 PM
- analyzed
- May 29, 2026, 10:58 PM
Related advisories
- alice-baileys@2.0.3 same package
- alice-baileys@2.0.2 same package
- alice-baileys@2.0.0 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.