LWA-2026-6777 confirmed malware
@risaoffc/baileys@8.0.3
Malicious code in @risaoffc/baileys (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Combosquat of the @whiskeysockets/baileys WhatsApp library. The package ships injected code in lib/Socket/newsletter.js that, on import, fetches a remote configuration from raw[.]githubusercontent[.]com/clarssafaqih-rgb/clarissa/refs/heads/main/risa.json and uses the victim's authenticated WhatsApp session to silently follow attacker-controlled newsletters and channels. The malicious IIFE runs at module scope with no lifecycle hook required.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 04:49 PM
- analyzed
- Jul 14, 2026, 04:50 PM
Related advisories
- chai-as-hardened@7.0.9
- @asyncapi/specs@6.11.2
- @asyncapi/generator-helpers@1.1.1
- eth-wallet-helpers@1.0.0
- core-dotenv@1.4.1
- http-ws-listener@1.0.5
- layer2-sdk@1.0.1
- eth-dev@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.