LWA-2026-1272 confirmed malware

alya-baileys@1.8.35

Malicious code in alya-baileys (npm)

Analysis

Trojanized WhatsApp (Baileys) fork: alya-baileys@1.8.35. (1) alya-decode.js exports AES-256-CBC decryption that derives keys from "socket-1.7.0" via a SHA-512->SHA-256->MD5 chain, used to decrypt URLs pointing to raw[.]githubusercontent[.]com. (2) newsletter.js:92-101 decrypts an encrypted URL at runtime via axios.get and fetches a remote config controlling WhatsApp auto-follow/auto-react botnet behaviour. (3) generics.js:280 fetches hxxps://raw[.]githubusercontent[.]com/ibradecode/socketon/master/lib/Defaults/baileys-version[.]json, an ibradecode/socketon C2 repo unrelated to the claimed diszx-creator/Baileys-alya origin. (4) Evasion: every core file imports the decryption module under 4-5 aliases (ibra_decode_21, ibraDecodePalsuMungkin, _ibra_decode_v21, ibra_decode_asli_nih). Remote code execution via a decrypted C2 URL.

analyzed by
Leitwacht
first seen
May 29, 2026, 11:56 PM
analyzed
May 29, 2026, 11:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.