{"id":"MAL-2026-17351","summary":"Malicious code in @bottino/baileys (npm)","details":"This package is part of a large family (100+ identified as of September 2026) of near-identical\nforks of the Baileys WhatsApp Web library that inject a covert channel-subscription action into\nthe WhatsApp socket layer. On connect, the injected code issues an authenticated `w:mex` FOLLOW\nquery (query_id 7871414976211147) against one or more attacker-chosen WhatsApp Channel/Newsletter\nJIDs, using the installer's own authenticated WhatsApp session -- silently subscribing the\nvictim's account to channels it never asked to join.\n\nThe target JID(s) are hidden from casual source review via one of several obfuscation techniques\nobserved across the family: a plain string literal, base64 encoding, base64+XOR, or a char-code\narray reconstructed at runtime. Some variants instead fetch a mutable, attacker-controlled remote\nJSON/JS list of target JIDs from GitHub or another host at runtime, letting the target list change\nafter installation without a new npm publish. Every sample in the family shares the same underlying\nmechanism (a wrapped/patched socket-connect routine that fires the FOLLOW query some seconds after\nconnect), even though the package name, JID value(s), and obfuscation/delivery method differ per\nfork.\n\nThe malicious action abuses the installer's own authenticated WhatsApp session to gain reach and\nsubscribers for attacker-controlled channels; it does not exfiltrate credentials, establish\npersistence, or execute arbitrary remote code.\n\nAffected package: @bottino/baileys (npm), version(s): 1.0.14, 1.0.13, 1.0.12, 1.0.11, 1.0.10, 1.0.9, 1.0.8, 1.0.7, 1.0.6, 1.0.5, 1.0.2, 1.0.1.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (571d52cf3274d95d4824667269921b2e0ad1478fe9f324a74fab0ba377bb9a26)\nThis fork of Baileys overrides `requestPairingCode` so that when the caller does not supply an explicit `pairKey`, `authState.creds.pairingCode` is set to the fixed literal string `BYPAKI64`. That value is then used as the KDF input for the WhatsApp companion-device link-code encryption via `derivePairingCodeKey(authState.creds.pairingCode, salt)`. Because the pairing code is a known constant baked into the package, anyone who knows the target phone number of the installer's WhatsApp account can complete the companion-device pair flow from a device they control and obtain persistent access to the installer's WhatsApp session (read/send messages, contacts, media) — a full account takeover backdoor against any application built on this library. Additionally, on socket connect the code auto-subscribes the installer's WhatsApp account to a hardcoded newsletter JID `120363418582531215@newsletter` and persists a `basedbysam` flag so the covert subscribe runs once per credential store; this covert action uses the installer's WhatsApp identity without disclosure.\n","modified":"2026-10-01T17:30:05.215393477Z","published":"2026-10-01T17:02:45Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-01T17:18:04.42009248Z","modified_time":"2026-10-01T17:03:15Z","sha256":"571d52cf3274d95d4824667269921b2e0ad1478fe9f324a74fab0ba377bb9a26","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-020870"},{"id":"IN-MAL-2026-020869","import_time":"2026-10-01T17:18:04.364806471Z","modified_time":"2026-10-01T17:03:04Z","sha256":"86b50651f18a57382f7092003d44fef58dd6dd5028786448ef66de864940d37f","source":"amazon-inspector","versions":["1.0.0"]},{"source":"amazon-inspector","versions":["1.0.5"],"id":"IN-MAL-2026-020867","import_time":"2026-10-01T17:18:04.260291119Z","modified_time":"2026-10-01T17:02:45Z","sha256":"cad4edc85fe2e1370c217c7a9b94b90a3b7be93f97529b2f83aad2ac411d2d32"}]},"references":[{"type":"ARTICLE","url":"https://www.ox.security/blog/phantomsub-malicious-npm-campaign-secretly-adds-users-to-whatsapp-spam-channels/"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@bottino/baileys/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@bottino/baileys/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@bottino/baileys/v/1.0.5"}],"affected":[{"package":{"name":"@bottino/baileys","ecosystem":"npm","purl":"pkg:npm/%40bottino/baileys"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.0.14","1.0.13","1.0.12","1.0.11","1.0.10","1.0.9","1.0.8","1.0.7","1.0.6","1.0.5","1.0.2","1.0.1","1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"f033c86b49b5153a8b7373759b277421f221e227224082a77fbc82211fb61d8d693fcd","path":"lib/Socket/socket.js","sha256":"9c40e0c861744f33f79091bb46d660b8db5efb63a0de7ab879eae8a97d7a2edf"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@bottino/baileys/MAL-2026-17351.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OX Security","type":"FINDER"}]}