LWA-2026-7115 confirmed malware
@dhyas23/dicitaz-baileys@1.0.0
Malicious code in @dhyas23/dicitaz-baileys (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
Package @dhyas23/dicitaz-baileys@1.0.0 is a combosquat of the real @whiskeysockets/baileys WhatsApp library. The postinstall hook runs 'node index.js', executing the package's main code at install time. The tarball is 795MB with 33,572 files — far larger than expected for a package with only a chalk dependency — and has no repository URL or description. The payload could not be statically inspected due to the tarball's size, but the combosquat name, install-time execution, and massive unexplained file count indicate a bundled malicious payload.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 06:43 AM
- analyzed
- Jul 25, 2026, 06:45 AM
Related advisories
- @kite-js-tools/core@1.0.0
- clerk-next-fix-auth-protection@7.7.7
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
- shift-sdk-v5@5.0.1
- shiftmarkets-sdk@2.1.0
- @cryptosrvc/shift-exchange-root@3.9.9
- @shiftmarkets/shift-sdk-v4@1.0.77
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.