alya-baileys@1.8.39
Malicious code in alya-baileys (npm)
Analysis
Trojanized WhatsApp bot library fork: alya-baileys@1.8.39 carries a live remote-config vector. newsletter.js decrypts a hardcoded AES-256-CBC blob (key derived from 'socket-1.7.0'+'ibrahimasli_bukanpalsu' via SHA512->SHA256->MD5) to reveal a raw[.]githubusercontent[.]com URL, then fetches config via axios on connection, controlling which newsletters to auto-follow and auto-react to. No credential theft and no eval/exec of fetched content. The preinstall hook is a benign Node.js version check. Multiple non-existent modules (ibra-decode.js, ibranihbossenggoldong.js) are required across many files. The attacker controls the GitHub raw content, making the encrypted remote-config fetch a C2 reconfiguration vector.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 11:58 PM
- analyzed
- May 30, 2026, 12:02 AM
Related advisories
- alya-baileys@1.8.42 same package
- alya-baileys@1.8.41 same package
- alya-baileys@1.8.40 same package
- alya-baileys@1.8.36 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.