LWA-2026-1277 confirmed malware

alya-baileys@1.8.41

Malicious code in alya-baileys (npm)

Analysis

WhatsApp engagement-farming bot with remote-control capability (Baileys fork). Ships alya-decode.js implementing AES-256-CBC with multi-layer key derivation (SHA512→SHA256→MD5, seed "socket-1.7.0_ibrahimasli_bukanpalsu") to decrypt hardcoded encrypted hex blobs into URLs. getTargetNewsletterFromExternal() decrypts an encrypted hex string ('632dfe2f...') to fetch remote config from raw[.]githubusercontent[.]com that controls which WhatsApp newsletters to auto-follow, what emoji reactions to auto-post, and poll-vote strategy. It subscribes to the messages.upsert event to auto-react and auto-vote on polls from attacker-controlled newsletters without user consent, and forces a newsletter follow of 120363407696889754@newsletter. Variable names use Indonesian slang and several files import a nonexistent ibra-decode module under aliases to hinder review. The preinstall hook (engine-requirements.js) is a benign Node version check.

analyzed by
Leitwacht
first seen
May 29, 2026, 11:59 PM
analyzed
May 30, 2026, 12:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.