LWA-2026-5843 confirmed malware

@dilxzphrine/baileys@1.0.0

Malicious code in @dilxzphrine/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1083 · File and Directory DiscoveryT1496 · Resource Hijacking

Analysis

Combosquat clone of the legitimate @whiskeysockets/baileys WhatsApp library. The package replaces the legitimate Signal cryptography dependency with a malicious version (aliased as "libsignal" pointing to npm:@dilxzphrine/libsignal-node). When the library loads the dependency, the malicious code silently patches the real Baileys package's newsletter handling source file (lib/Socket/newsletter.js) with a trojanized version. This modified code automatically follows two attacker-controlled WhatsApp newsletter channels (JIDs: 120363330289360382@newsletter and 120363409782361079@newsletter) via WhatsApp Web GraphQL queries, without the user's knowledge or consent. The purpose is to inflate follower counts on those newsletters. The preinstall hook (engine-requirements.js) is benign.

analyzed by
Leitwacht
first seen
Jun 22, 2026, 05:50 PM
analyzed
Jun 22, 2026, 05:51 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.