@dilxzphrine/baileys@1.0.0
Malicious code in @dilxzphrine/baileys (npm)
Analysis
Combosquat clone of the legitimate @whiskeysockets/baileys WhatsApp library. The package replaces the legitimate Signal cryptography dependency with a malicious version (aliased as "libsignal" pointing to npm:@dilxzphrine/libsignal-node). When the library loads the dependency, the malicious code silently patches the real Baileys package's newsletter handling source file (lib/Socket/newsletter.js) with a trojanized version. This modified code automatically follows two attacker-controlled WhatsApp newsletter channels (JIDs: 120363330289360382@newsletter and 120363409782361079@newsletter) via WhatsApp Web GraphQL queries, without the user's knowledge or consent. The purpose is to inflate follower counts on those newsletters. The preinstall hook (engine-requirements.js) is benign.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 05:50 PM
- analyzed
- Jun 22, 2026, 05:51 PM
Related advisories
- @dilxzphrine/libsignal-node@2.5.0
- xeiko-cdn@1.0.0
- mev-shield@1.4.2
- fb-cards-form-no-resident-information@20.4.4
- crypto-base58@1.0.1
- zhuanhua@1.1.99
- sync-external@1.6.0
- atlasora-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.