@kkael/baileys@8.0.8
Malicious code in @kkael/baileys (npm)
Analysis
@kkael/baileys is a trojanized clone of the legitimate @whiskeysockets/baileys WhatsApp library. The package ships an injected payload in lib/Utils/messages-media.js that decodes a base64-encoded URL pointing to raw[.]githubusercontent[.]com/Kkael-0xf/Kael-Database/refs/heads/main/Private.json, fetches the JSON after a 60-second delay, and iterates over the returned IDs to perform newsletter-follow actions every 5 seconds. The payload executes at require-time when lib/Socket/newsletter.js imports and calls loadBase(). The package also replaces the legitimate signal library dependency with @skycodee/libsignal, a known-malicious package.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 10:04 AM
- analyzed
- Jul 12, 2026, 10:05 AM
Related advisories
- dotnet-runtime-base@1.0.5
- frontend-regulations@99.9.1
- sso-users-detection@99.9.1
- tinyparrot@0.4.1
- svg-fetcher@2.4.1
- cookie-sign@2.3.5
- react-hot-svg@1.1.5
- polymarket-kelly-math-stake@3.6.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.