alya-baileys@1.8.41
Malicious code in alya-baileys (npm)
Analysis
WhatsApp engagement-farming bot with remote-control capability (Baileys fork). Ships alya-decode.js implementing AES-256-CBC with multi-layer key derivation (SHA512→SHA256→MD5, seed "socket-1.7.0_ibrahimasli_bukanpalsu") to decrypt hardcoded encrypted hex blobs into URLs. getTargetNewsletterFromExternal() decrypts an encrypted hex string ('632dfe2f...') to fetch remote config from raw[.]githubusercontent[.]com that controls which WhatsApp newsletters to auto-follow, what emoji reactions to auto-post, and poll-vote strategy. It subscribes to the messages.upsert event to auto-react and auto-vote on polls from attacker-controlled newsletters without user consent, and forces a newsletter follow of 120363407696889754@newsletter. Variable names use Indonesian slang and several files import a nonexistent ibra-decode module under aliases to hinder review. The preinstall hook (engine-requirements.js) is a benign Node version check.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 11:59 PM
- analyzed
- May 30, 2026, 12:05 AM
Related advisories
- alya-baileys@1.8.42 same package
- alya-baileys@1.8.40 same package
- alya-baileys@1.8.39 same package
- alya-baileys@1.8.36 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.