@ranstech/baileys@6.1.0
Malicious code in @ranstech/baileys (npm)
Analysis
Package @ranstech/baileys is a combosquat impersonating the legitimate @whiskeysockets/baileys WhatsApp API library. It ships a forked clone of the real codebase with injected behaviour: on every require(), it fetches a JSON payload from raw[.]githubusercontent[.]com/rans-beep/Bailss/refs/heads/main/infojir.json and logs content to the console. While the current payload is an innocuous message, the endpoint is attacker-controlled and could be silently updated at any time. The package has no public source repository — the homepage links only to the npm registry page — making the code unauditable outside the tarball. The dependency libsignal is pinned to a non-official GitHub fork (github:@alannzxd/libsignal-node).
- analyzed by
- Leitwacht
- first seen
- Jun 27, 2026, 12:11 PM
- analyzed
- Jun 27, 2026, 12:12 PM
Related advisories
- chai-as-persisted@4.2.8
- react-dynammic-table-component@1.2.7
- react-dynamic-table-compenent@1.2.7
- gptmini@4.0.2
- chai-as-assured@7.1.2
- rollup-plugin-polyfill-handler@1.0.0
- ts-einkle-slot@0.0.8
- ts-einkle@1.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.