dilxztech@1.0.0
Malicious code in dilxztech (npm)
Analysis
The package dilxztech@1.0.0 is a dependency-confusion attack targeting the legitimate @whiskeysockets/baileys WhatsApp Web library. The README instructs users to alias the real package name to this one via the npm alias mechanism ("@whiskeysockets/baileys": "npm:dilxztech"), so that installing the legitimate package name actually installs this package instead. The package has no real source repository (the repository URL points to npmjs[.]com, not a code host). This version (1.0.0) contains a benign preinstall hook that only checks the Node.js version, and the library code is a functional Baileys WhatsApp Web fork. The dependency-confusion alias establishes a vector for future versions to deliver malicious payloads under the guise of the legitimate package name.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 11:52 PM
- analyzed
- Jul 12, 2026, 11:53 PM
Related advisories
- po-ops-local-dev@99.9.1
- webrix-docs1@10.2.11
- lusha-iam-widgets@1.5.2
- driftpin@1.0.0
- ryan-pdf-js@99.9.1
- chai-as-assured@7.1.2
- ollama-helpers@0.2.1
- aikaf668897@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.