{"id":"MAL-2026-17362","summary":"Malicious code in @kelvdra/baileys (npm)","details":"This package is part of a large family (100+ identified as of September 2026) of near-identical\nforks of the Baileys WhatsApp Web library that inject a covert channel-subscription action into\nthe WhatsApp socket layer. On connect, the injected code issues an authenticated `w:mex` FOLLOW\nquery (query_id 7871414976211147) against one or more attacker-chosen WhatsApp Channel/Newsletter\nJIDs, using the installer's own authenticated WhatsApp session -- silently subscribing the\nvictim's account to channels it never asked to join.\n\nThe target JID(s) are hidden from casual source review via one of several obfuscation techniques\nobserved across the family: a plain string literal, base64 encoding, base64+XOR, or a char-code\narray reconstructed at runtime. Some variants instead fetch a mutable, attacker-controlled remote\nJSON/JS list of target JIDs from GitHub or another host at runtime, letting the target list change\nafter installation without a new npm publish. Every sample in the family shares the same underlying\nmechanism (a wrapped/patched socket-connect routine that fires the FOLLOW query some seconds after\nconnect), even though the package name, JID value(s), and obfuscation/delivery method differ per\nfork.\n\nThe malicious action abuses the installer's own authenticated WhatsApp session to gain reach and\nsubscribers for attacker-controlled channels; it does not exfiltrate credentials, establish\npersistence, or execute arbitrary remote code.\n\nAffected package: @kelvdra/baileys (npm), version(s): 1.0.6-rc.1, 1.0.6, 1.0.5-rc.3.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (839545967c959062f79d5b217758730bd2c6a69219949c2eea494e75e3cfc12a)\npackage.json in @kelvdra/baileys@1.0.6-rc.4 declares the dependency `libsignal` as `github:Kelvdra/libsignal` with no version, tag, or commit SHA. On `npm install`, npm resolves this specifier to the current tip of the referenced repository's default branch and installs whatever bytes it returns, running any lifecycle scripts contained within them, with no integrity check. The dependency source is not the npm registry and not a pinned commit, so the code that lands on the installer's machine can change at any moment without any change to this package. Control of that GitHub account or repository translates directly into install-time code execution on every installer of this package.\n","modified":"2026-10-01T17:30:05.227285759Z","published":"2026-10-01T17:02:55Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-01T17:18:04.314207215Z","modified_time":"2026-10-01T17:02:55Z","sha256":"839545967c959062f79d5b217758730bd2c6a69219949c2eea494e75e3cfc12a","source":"amazon-inspector","versions":["1.0.6-rc.4"],"id":"IN-MAL-2026-020868"}]},"references":[{"type":"ARTICLE","url":"https://www.ox.security/blog/phantomsub-malicious-npm-campaign-secretly-adds-users-to-whatsapp-spam-channels/"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kelvdra/baileys/v/1.0.6-rc.4"}],"affected":[{"package":{"name":"@kelvdra/baileys","ecosystem":"npm","purl":"pkg:npm/%40kelvdra/baileys"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.0.6-rc.1","1.0.6","1.0.5-rc.3","1.0.6-rc.4"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"bb41ad11ca798cf305e532e868e65003a5304a479c58bc3c379d83ac9f8e25f77baa5d","path":"package.json","sha256":"76ffcc4611eed87ec41e5c51d2cf17f07a2a98bed50de91dc06a278d23c79456"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-leeWcoBw7hc/st5huMT3IUvAr+jjT6zyxM7XbBy10Mm5BqDIHJy3/yNSZIg/arLyTO9qF/n557FSy9yFdEDbIQ==","sha1":"f4da41c3c18c4029ddc69f2fb10efb519aba771c"},"filename":"baileys-1.0.6-rc.4.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@kelvdra/baileys/MAL-2026-17362.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OX Security","type":"FINDER"}]}