{"id":"MAL-2026-17341","summary":"Malicious code in @badzz88/baileys (npm)","details":"This package is part of a large family (100+ identified as of September 2026) of near-identical\nforks of the Baileys WhatsApp Web library that inject a covert channel-subscription action into\nthe WhatsApp socket layer. On connect, the injected code issues an authenticated `w:mex` FOLLOW\nquery (query_id 7871414976211147) against one or more attacker-chosen WhatsApp Channel/Newsletter\nJIDs, using the installer's own authenticated WhatsApp session -- silently subscribing the\nvictim's account to channels it never asked to join.\n\nThe target JID(s) are hidden from casual source review via one of several obfuscation techniques\nobserved across the family: a plain string literal, base64 encoding, base64+XOR, or a char-code\narray reconstructed at runtime. Some variants instead fetch a mutable, attacker-controlled remote\nJSON/JS list of target JIDs from GitHub or another host at runtime, letting the target list change\nafter installation without a new npm publish. Every sample in the family shares the same underlying\nmechanism (a wrapped/patched socket-connect routine that fires the FOLLOW query some seconds after\nconnect), even though the package name, JID value(s), and obfuscation/delivery method differ per\nfork.\n\nThe malicious action abuses the installer's own authenticated WhatsApp session to gain reach and\nsubscribers for attacker-controlled channels; it does not exfiltrate credentials, establish\npersistence, or execute arbitrary remote code.\n\nAffected package: @badzz88/baileys (npm), version(s): 8.5.9, 8.5.7, 8.5.5, 8.5.4, 8.5.3, 8.5.2, 8.5.1.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8c4fc02c3ef351d891d52e60719cbd702d2f6a1db2d00847ac02ae7928de67b9)\npackage.json declares a required runtime dependency `whatsapp-rust-bridge-baron` resolved to `github:7ucg/whatsapp-rust-bridge` with no commit SHA, tag, or integrity hash. On `npm install`, npm fetches the current default-branch HEAD of that repository and installs it into node_modules. The GitHub account `7ucg` is not the publisher of this npm package (published under `Badzz88`), so an unrelated third party controls the code that lands on the installer's machine. The bridge module is required throughout the crypto, decode, and Noise-handler paths, so its code executes as soon as a consumer imports the package. Because the source is a mutable branch owned by a non-publisher account, the fetched bytes can change silently between installs, and there is no verification that today's HEAD matches any previously reviewed content. This is the classic unpinned-mutable-source install-time code-execution channel. Additional network/child_process/os primitives referenced in src/Utils/generics.js and src/Utils/messages-media.js are consistent with the upstream Baileys library shape (media download, ping-based connectivity checks) and are not by themselves evidence of exfiltration in this fork.\n","modified":"2026-10-06T04:30:47.846369794Z","published":"2026-10-06T04:00:48Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-06T04:22:56.624357377Z","modified_time":"2026-10-06T04:00:48Z","sha256":"8c4fc02c3ef351d891d52e60719cbd702d2f6a1db2d00847ac02ae7928de67b9","source":"amazon-inspector","versions":["8.4.9"],"id":"IN-MAL-2026-021095"},{"sha256":"c3bccadaa96c2ad529ff66b4cfaa19f5711a9443f9754aabc4f4abc9c580a81d","source":"amazon-inspector","versions":["8.6.0"],"id":"IN-MAL-2026-021096","import_time":"2026-10-06T04:22:56.687395631Z","modified_time":"2026-10-06T04:02:12Z"}]},"references":[{"type":"ARTICLE","url":"https://www.ox.security/blog/phantomsub-malicious-npm-campaign-secretly-adds-users-to-whatsapp-spam-channels/"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@badzz88/baileys/v/8.4.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@badzz88/baileys/v/8.6.0"}],"affected":[{"package":{"name":"@badzz88/baileys","ecosystem":"npm","purl":"pkg:npm/%40badzz88/baileys"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["8.5.9","8.5.7","8.5.5","8.5.4","8.5.3","8.5.2","8.5.1","8.4.9","8.6.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@badzz88/baileys/MAL-2026-17341.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"83d310f6ed1deaf41af90c4547102eeef09f548fd9592ed6ce55743d00dc3f20","tlsh":"3d51f075cc18cd6306c666deb879524164281d475c82fc2cb3a943ad8f1d29f32b5b7c","path":"package.json"}],"package_integrity":[{"filename":"baileys-8.4.9.tgz","hashes":{"sha1":"8856be686093fd186ae1e8e9e3f601cc23edcbe9","sha512_sri":"sha512-4+efijE8gsSqSFzr0Jvs4+iVqF+7q5ZYFJTC4e/CNqrttEO84XPQuH10BrIUhT81CH7wT+YAk5IF9vwYIhRrRQ=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OX Security","type":"FINDER"}]}