LWA-2026-6777 confirmed malware

@risaoffc/baileys@8.0.3

Malicious code in @risaoffc/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat of the @whiskeysockets/baileys WhatsApp library. The package ships injected code in lib/Socket/newsletter.js that, on import, fetches a remote configuration from raw[.]githubusercontent[.]com/clarssafaqih-rgb/clarissa/refs/heads/main/risa.json and uses the victim's authenticated WhatsApp session to silently follow attacker-controlled newsletters and channels. The malicious IIFE runs at module scope with no lifecycle hook required.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 04:49 PM
analyzed
Jul 14, 2026, 04:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.