{"id":"MAL-2026-10665","summary":"Malicious code in @fhkry/x-baileys (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (db9f6c3e5c391d9d3ffeb7f6c1b4154b0266efeb73bdf5543ad81f50236bdabc)\nThis package presents itself as a fork of @whiskeysockets/baileys (impersonating the original author 'Adhiraj Singh' in package.json and exposing the same makeWASocket API surface) but adds undocumented covert behavior in lib/Socket/newsletter.js. Two side effects fire on any consumer that creates a WhatsApp socket with this library:\n\n1. A setTimeout 120 seconds after socket creation base64-decodes a hardcoded URL (https://raw.githubusercontent.com/Fhkryy/Fhkry/refs/heads/main/peler.json) — the URL is stored as the base64 literal `aHR0cHM6Ly9yYXcuZ2l0aHVidXNlcmNvbnRlbnQuY29tL0Zoa3J5eS9GaGtyeS9yZWZzL2hlYWRzL21haW4vcGVsZXIuanNvbg==` to hide it from casual inspection. The fetched JSON contains base64-encoded WhatsApp newsletter IDs, and the code silently calls newsletterWMexQuery(id, QueryIds.FOLLOW) for each one using the installer's authenticated WhatsApp account.\n\n2. A `connection.update` handler invokes autoJoinWhatsAppGroups when the connection opens, iterating a hardcoded list (currently `https://chat.whatsapp.com/C8n8s4Yj1G42wdkAwDP7rP`) and calling sock.groupAcceptInvite / groupAcceptInviteV4 to silently join attacker-chosen WhatsApp groups under the installer's identity.\n\nBoth lists are mutable (raw.githubusercontent.com main branch + package updates), so the attacker can rotate destinations at will. Every developer using this library to run a WhatsApp bot has their account hijacked into following newsletters and joining groups of the attacker's choosing — a silent-relay of the consumer's WhatsApp identity to attacker-curated spaces. The package's homepage field points to a different scope (`@fhkryy/x-baileys`) than the package name (`@fhkry/x-baileys`), and the author field falsely names the original Baileys maintainer, confirming impersonation intent.\n\n## Source: ghsa-malware (41cbffddc905c0088db2c4c3278d560592d468e9c6e762a626e2755c51d4ae85)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n","aliases":["GHSA-mxxc-f6p6-98j7"],"modified":"2026-07-15T10:49:21.442529570Z","published":"2026-07-15T06:35:37Z","database_specific":{"malicious-packages-origins":[{"id":"GHSA-mxxc-f6p6-98j7","modified_time":"2026-07-15T06:35:38Z","ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"source":"ghsa-malware","sha256":"41cbffddc905c0088db2c4c3278d560592d468e9c6e762a626e2755c51d4ae85","import_time":"2026-07-15T07:00:48.967612564Z"},{"id":"IN-MAL-2026-010662","modified_time":"2026-07-15T10:30:33Z","versions":["1.3.0"],"source":"amazon-inspector","sha256":"59f5661d2d11aa73c9096f204145a77a7da3ba1d3c557397c8b2b2ba76959bf4","import_time":"2026-07-15T10:36:58.249967971Z"},{"modified_time":"2026-07-15T10:30:50Z","versions":["1.4.0"],"source":"amazon-inspector","sha256":"792fa423311100360a47c94deb45941a31d8477b338b3942057632daf9942f88","import_time":"2026-07-15T10:36:58.305566209Z","id":"IN-MAL-2026-010664"},{"id":"IN-MAL-2026-010663","modified_time":"2026-07-15T10:30:42Z","versions":["1.0.0"],"source":"amazon-inspector","sha256":"db9f6c3e5c391d9d3ffeb7f6c1b4154b0266efeb73bdf5543ad81f50236bdabc","import_time":"2026-07-15T10:36:58.276529246Z"},{"sha256":"e9c2021e32488300a8185c3bee6ac43932b5e41a6e60f3ac642e019c8f06b135","import_time":"2026-07-15T10:36:58.217518142Z","id":"IN-MAL-2026-010661","modified_time":"2026-07-15T10:30:10Z","versions":["1.7.0"],"source":"amazon-inspector"},{"modified_time":"2026-07-15T10:30:58Z","versions":["1.1.0"],"source":"amazon-inspector","sha256":"0ee7c254668ea82b020b5d3fcd987ede890692960892b99022316968037eecd6","import_time":"2026-07-15T10:36:58.335659442Z","id":"IN-MAL-2026-010665"},{"sha256":"2defc61fd60e212de19b24626841b394c313db6d050fe871c4f806154fffe8f5","import_time":"2026-07-15T10:36:58.498369019Z","id":"IN-MAL-2026-010669","modified_time":"2026-07-15T10:31:37Z","versions":["1.6.0"],"source":"amazon-inspector"},{"id":"IN-MAL-2026-010666","modified_time":"2026-07-15T10:31:08Z","versions":["1.2.0"],"source":"amazon-inspector","sha256":"4fac69d3087ea9f4aaf0c92afa6da8102bef1500d818b6fa4bc167cce394bdbe","import_time":"2026-07-15T10:36:58.367243485Z"},{"source":"amazon-inspector","sha256":"5621a9e8450b1d8dfce3637d314d245060a8ecb76157dbf09b53276e2d00cb07","import_time":"2026-07-15T10:36:58.421524877Z","id":"IN-MAL-2026-010667","modified_time":"2026-07-15T10:31:17Z","versions":["1.5.0"]}]},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mxxc-f6p6-98j7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@fhkry/x-baileys/v/1.3.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@fhkry/x-baileys/v/1.4.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@fhkry/x-baileys/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@fhkry/x-baileys/v/1.7.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@fhkry/x-baileys/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@fhkry/x-baileys/v/1.6.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@fhkry/x-baileys/v/1.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@fhkry/x-baileys/v/1.5.0"}],"affected":[{"package":{"name":"@fhkry/x-baileys","ecosystem":"npm","purl":"pkg:npm/%40fhkry/x-baileys"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.3.0","1.4.0","1.0.0","1.7.0","1.1.0","1.6.0","1.2.0","1.5.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"62fc85c6480874f60b69aff1baebbf5b35105c27fa26ff2c5dc71d8d40d45321","tlsh":"7372b89565fa56a616b37054aa7fb0e0b321f2437955d8663f8cc4020f4a2dcf8b3bd8","path":"lib/Socket/newsletter.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@fhkry/x-baileys/MAL-2026-10665.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}