LWA-2026-1278 confirmed malware

alya-baileys@1.8.42

Malicious code in alya-baileys (npm)

Analysis

WhatsApp bot wrapper (Baileys fork) containing an embedded C2 backdoor. newsletter.js constructs hxxps://raw[.]githubcontent-content[.]com (a typosquat of raw[.]githubusercontent[.]com) from hex bytes, derives an AES key from it, decrypts an embedded ciphertext to a C2 URL, and fetches remote config via axios at runtime to control newsletter auto-follow/auto-react behavior (engagement farming/spam). alya-decode.js implements custom AES-256-CBC with obfuscated Indonesian variable names. The typosquat domain plus encrypted C2 URL and runtime remote-config fetch form a C2 pattern.

analyzed by
Leitwacht
first seen
May 29, 2026, 11:59 PM
analyzed
May 30, 2026, 12:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.