LWA-2026-1275 confirmed malware

alya-baileys@1.8.39

Malicious code in alya-baileys (npm)

Analysis

Trojanized WhatsApp bot library fork: alya-baileys@1.8.39 carries a live remote-config vector. newsletter.js decrypts a hardcoded AES-256-CBC blob (key derived from 'socket-1.7.0'+'ibrahimasli_bukanpalsu' via SHA512->SHA256->MD5) to reveal a raw[.]githubusercontent[.]com URL, then fetches config via axios on connection, controlling which newsletters to auto-follow and auto-react to. No credential theft and no eval/exec of fetched content. The preinstall hook is a benign Node.js version check. Multiple non-existent modules (ibra-decode.js, ibranihbossenggoldong.js) are required across many files. The attacker controls the GitHub raw content, making the encrypted remote-config fetch a C2 reconfiguration vector.

analyzed by
Leitwacht
first seen
May 29, 2026, 11:58 PM
analyzed
May 30, 2026, 12:02 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.