LWA-2026-6040 confirmed malware

@ranstech/baileys@6.1.0

Malicious code in @ranstech/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Package @ranstech/baileys is a combosquat impersonating the legitimate @whiskeysockets/baileys WhatsApp API library. It ships a forked clone of the real codebase with injected behaviour: on every require(), it fetches a JSON payload from raw[.]githubusercontent[.]com/rans-beep/Bailss/refs/heads/main/infojir.json and logs content to the console. While the current payload is an innocuous message, the endpoint is attacker-controlled and could be silently updated at any time. The package has no public source repository — the homepage links only to the npm registry page — making the code unauditable outside the tarball. The dependency libsignal is pinned to a non-official GitHub fork (github:@alannzxd/libsignal-node).

analyzed by
Leitwacht
first seen
Jun 27, 2026, 12:11 PM
analyzed
Jun 27, 2026, 12:12 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.