LWA-2026-6634 confirmed malware

@kkael/baileys@8.0.8

Malicious code in @kkael/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

@kkael/baileys is a trojanized clone of the legitimate @whiskeysockets/baileys WhatsApp library. The package ships an injected payload in lib/Utils/messages-media.js that decodes a base64-encoded URL pointing to raw[.]githubusercontent[.]com/Kkael-0xf/Kael-Database/refs/heads/main/Private.json, fetches the JSON after a 60-second delay, and iterates over the returned IDs to perform newsletter-follow actions every 5 seconds. The payload executes at require-time when lib/Socket/newsletter.js imports and calls loadBase(). The package also replaces the legitimate signal library dependency with @skycodee/libsignal, a known-malicious package.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 10:04 AM
analyzed
Jul 12, 2026, 10:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.