LWA-2026-6940 confirmed malware

@queenanya/baileys@9.7.1

Malicious code in @queenanya/baileys (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

Combosquat of the @whiskeysockets/baileys WhatsApp Web library. The package ships cloned code from the legitimate library but replaces the 'libsignal' dependency with a custom tarball hosted under the attacker's npm scope (@queenanya/libsignal). It also declares a dependency on 'whatsapp-rust-bridge@0.5.5' which does not exist on the public npm registry. The preinstall hook is a benign Node.js version check; the malicious payload is delivered through the substituted dependency chain rather than in the package source itself.

analyzed by
Leitwacht
first seen
Jul 18, 2026, 05:58 AM
analyzed
Jul 18, 2026, 05:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.