alya-baileys@1.8.40
Malicious code in alya-baileys (npm)
Analysis
Trojanized Baileys WhatsApp bot fork: alya-baileys@1.8.40. newsletter.js + alaya-decode.js implement AES-256-CBC decryption (key derived from the hardcoded seed 'socketon-1.7.0_ibrahimasli_bukanpalsu') that runtime-decrypts a URL, fetches remote config via axios, and uses it to auto-follow WhatsApp newsletters and auto-react to their messages; _ensureFollow() runs on connection.open with a 30s polling interval. The preinstall script is a benign node version check. The remote config can be changed post-publication to serve different instructions: engagement-farming behaviour with a C2 channel.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 11:58 PM
- analyzed
- May 30, 2026, 12:03 AM
Related advisories
- alya-baileys@1.8.42 same package
- alya-baileys@1.8.41 same package
- alya-baileys@1.8.39 same package
- alya-baileys@1.8.36 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.