alya-baileys@1.8.42
Malicious code in alya-baileys (npm)
Analysis
WhatsApp bot wrapper (Baileys fork) containing an embedded C2 backdoor. newsletter.js constructs hxxps://raw[.]githubcontent-content[.]com (a typosquat of raw[.]githubusercontent[.]com) from hex bytes, derives an AES key from it, decrypts an embedded ciphertext to a C2 URL, and fetches remote config via axios at runtime to control newsletter auto-follow/auto-react behavior (engagement farming/spam). alya-decode.js implements custom AES-256-CBC with obfuscated Indonesian variable names. The typosquat domain plus encrypted C2 URL and runtime remote-config fetch form a C2 pattern.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 11:59 PM
- analyzed
- May 30, 2026, 12:06 AM
Related advisories
- alya-baileys@1.8.41 same package
- alya-baileys@1.8.40 same package
- alya-baileys@1.8.39 same package
- alya-baileys@1.8.36 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.