LWA-2026-6940 confirmed malware
@queenanya/baileys@9.7.1
Malicious code in @queenanya/baileys (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
Combosquat of the @whiskeysockets/baileys WhatsApp Web library. The package ships cloned code from the legitimate library but replaces the 'libsignal' dependency with a custom tarball hosted under the attacker's npm scope (@queenanya/libsignal). It also declares a dependency on 'whatsapp-rust-bridge@0.5.5' which does not exist on the public npm registry. The preinstall hook is a benign Node.js version check; the malicious payload is delivered through the substituted dependency chain rather than in the package source itself.
- analyzed by
- Leitwacht
- first seen
- Jul 18, 2026, 05:58 AM
- analyzed
- Jul 18, 2026, 05:59 AM
Related advisories
- @cr-invested-ui-components/chart@99.9.1
- utils-style-engine@10.2.4
- dilxztech@1.0.0
- po-ops-local-dev@99.9.1
- webrix-docs1@10.2.11
- lusha-iam-widgets@1.5.2
- driftpin@1.0.0
- ryan-pdf-js@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.