{"id":"MAL-2026-17311","summary":"Malicious code in itsmeeaizat-bailey (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e87b4292727088efa5df8326a5f868b2c6bb3ae66ee15cecc18f2fa899296075)\npackage.json declares the `libsignal` dependency as `git+https://github.com/whiskeysockets/libsignal-node` with no tag, no commit SHA, and no integrity constraint. On `npm install`, this resolves to whatever the default branch HEAD currently points at and executes any lifecycle scripts inside that fetched tree on the installer's machine — the delivered bytes and their behavior can change at any moment without a version bump to this package. Separately, the default socket factory in this Baileys fork wires an on-connection hook that, roughly 90 seconds after the installer's WhatsApp session opens, silently issues a FOLLOW MEX query for the hardcoded newsletter JID `120363400911374213@newsletter`, which is owned by the package author. The behavior is not documented in the README and is only disableable via an undocumented `autoFollowNewsletterOnConnect:false` option, so the installer's authenticated WhatsApp identity is used to perform a social reach-padding action they did not opt into. No credential theft, exfiltration to an author endpoint, backdoor, or install-time destructive action is present in the shipped code.\n","modified":"2026-09-30T10:32:25.703942457Z","published":"2026-09-30T01:46:43Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-30T02:52:56.39972635Z","modified_time":"2026-09-30T01:46:53Z","sha256":"aa89fc4b6ac9b670004406f8d95eee96891afc83758b023cf6fdeb23c70abcdc","source":"amazon-inspector","versions":["1.0.4"],"id":"IN-MAL-2026-020789"},{"sha256":"d33df45ab827c11b7a27184ffdfe922765eaafb919cd6908cdc715453cadbeac","source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-020788","import_time":"2026-09-30T02:52:56.295456306Z","modified_time":"2026-09-30T01:46:43Z"},{"modified_time":"2026-09-30T01:47:20Z","sha256":"e87b4292727088efa5df8326a5f868b2c6bb3ae66ee15cecc18f2fa899296075","source":"amazon-inspector","versions":["1.0.5"],"id":"IN-MAL-2026-020792","import_time":"2026-09-30T02:52:56.775390735Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/itsmeeaizat-bailey/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/itsmeeaizat-bailey/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/itsmeeaizat-bailey/v/1.0.5"}],"affected":[{"package":{"name":"itsmeeaizat-bailey","ecosystem":"npm","purl":"pkg:npm/itsmeeaizat-bailey"},"versions":["1.0.4","1.0.3","1.0.5"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"e66a37f396de0be47cd4fd0f3df4e2376a2b3035","sha512_sri":"sha512-/oa5I9aiTmqxMQDGsFvz23eCv6ol5siP7KdIA0k8eXqQFfk8mtiZXMqu/W2Gs0MWBMXtVZZ2woT5klENosG1WQ=="},"filename":"itsmeeaizat-bailey-1.0.4.tgz"}],"evidence_files":[{"path":"package.json","sha256":"042cfd491fa93d75cbc274de488d0cea367a0a3f1b3862b7bb28e655a585b223","tlsh":"6441ba24cc289eb305c526e8acba4102e57069538d44fc2c73c9432c8f8d15f7bbabad"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/itsmeeaizat-bailey/MAL-2026-17311.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OX Security","type":"FINDER"}]}