vourfly-tele@4.7.6
Malicious code in vourfly-tele (npm)
Analysis
vourfly-tele is a trojanized clone of the Baileys WhatsApp Web library containing a destructive wiper payload. The package ships a hardcoded GitHub personal access token in a dependency URL (node-pkg-cache pointing to github[.]com/navaLinh/sysframe) used to fetch malicious code from a private repository. In package/lib/Socket/socket.js, the requestPairingCode function decodes a base64 URL (raw[.]githubusercontent[.]com/navaLinh/database/main/seska.json), fetches a phone-number allowlist, and if the user's phone number is not on that list, executes 'rm -rf *' to wipe the current working directory. Additional injected dependencies include axios, child_process.exec, and node-fetch.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 09:28 PM
- analyzed
- Jun 15, 2026, 09:30 PM
Related advisories
- vite-plugin-vue-extend@1.0.9
- vite-plugin-bomb-extend@2.0.0
- vite-plugin-bomb@2.0.0
- super-test-json@1.2.0
- pwdyx@1.0.9
- osinthell@1.9.5
- express-dever@5.1.7
- @web3-helpers/core@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.