LWA-2026-6649 confirmed malware

dilxztech@1.0.0

Malicious code in dilxztech (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

The package dilxztech@1.0.0 is a dependency-confusion attack targeting the legitimate @whiskeysockets/baileys WhatsApp Web library. The README instructs users to alias the real package name to this one via the npm alias mechanism ("@whiskeysockets/baileys": "npm:dilxztech"), so that installing the legitimate package name actually installs this package instead. The package has no real source repository (the repository URL points to npmjs[.]com, not a code host). This version (1.0.0) contains a benign preinstall hook that only checks the Node.js version, and the library code is a functional Baileys WhatsApp Web fork. The dependency-confusion alias establishes a vector for future versions to deliver malicious payloads under the guise of the legitimate package name.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 11:52 PM
analyzed
Jul 12, 2026, 11:53 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.