LWA-2026-1274 confirmed malware

alya-baileys@1.8.36

Malicious code in alya-baileys (npm)

Analysis

Trojanized Baileys WhatsApp fork: alya-baileys@1.8.36. (1) A custom AES-256-CBC module (alya-decode.js) derives keys via SHA512->SHA256->MD5 from an obfuscated hex seed "socket-1.7.0" + "_ibrahimasli_bukanpalsu". (2) newsletter.js calls the decryptor at module load time to decode encrypted payloads into URLs, then fetches them via axios as a C2 channel; the decrypted URL targets raw[.]githubcontent-content[.]com, a typosquat of raw[.]githubusercontent[.]com. (3) alyachan.js contains the same AES routine with a hex-obfuscated URL to the same typosquat domain. (4) The newsletter auto-react/auto-vote system is configurable via the remote fetched config, enabling dynamic C2 reconfiguration. (5) ~15 source files carry duplicate require("./ibra-decode") lines for a file absent from the tarball (cargo-cult obfuscation).

analyzed by
Leitwacht
first seen
May 29, 2026, 11:57 PM
analyzed
May 29, 2026, 11:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.