LWA-2026-1276 confirmed malware

alya-baileys@1.8.40

Malicious code in alya-baileys (npm)

Analysis

Trojanized Baileys WhatsApp bot fork: alya-baileys@1.8.40. newsletter.js + alaya-decode.js implement AES-256-CBC decryption (key derived from the hardcoded seed 'socketon-1.7.0_ibrahimasli_bukanpalsu') that runtime-decrypts a URL, fetches remote config via axios, and uses it to auto-follow WhatsApp newsletters and auto-react to their messages; _ensureFollow() runs on connection.open with a 30s polling interval. The preinstall script is a benign node version check. The remote config can be changed post-publication to serve different instructions: engagement-farming behaviour with a C2 channel.

analyzed by
Leitwacht
first seen
May 29, 2026, 11:58 PM
analyzed
May 30, 2026, 12:03 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.