LWA-2026-5442 confirmed malware

vourfly-tele@4.7.6

Malicious code in vourfly-tele (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1552.001 · Credentials In FilesT1485 · Data DestructionT1082 · System Information Discovery

Analysis

vourfly-tele is a trojanized clone of the Baileys WhatsApp Web library containing a destructive wiper payload. The package ships a hardcoded GitHub personal access token in a dependency URL (node-pkg-cache pointing to github[.]com/navaLinh/sysframe) used to fetch malicious code from a private repository. In package/lib/Socket/socket.js, the requestPairingCode function decodes a base64 URL (raw[.]githubusercontent[.]com/navaLinh/database/main/seska.json), fetches a phone-number allowlist, and if the user's phone number is not on that list, executes 'rm -rf *' to wipe the current working directory. Additional injected dependencies include axios, child_process.exec, and node-fetch.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 09:28 PM
analyzed
Jun 15, 2026, 09:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.