{"id":"MAL-2026-17397","summary":"Malicious code in levvleys (npm)","details":"This package is part of a large family (100+ identified as of September 2026) of near-identical\nforks of the Baileys WhatsApp Web library that inject a covert channel-subscription action into\nthe WhatsApp socket layer. On connect, the injected code issues an authenticated `w:mex` FOLLOW\nquery (query_id 7871414976211147) against one or more attacker-chosen WhatsApp Channel/Newsletter\nJIDs, using the installer's own authenticated WhatsApp session -- silently subscribing the\nvictim's account to channels it never asked to join.\n\nThe target JID(s) are hidden from casual source review via one of several obfuscation techniques\nobserved across the family: a plain string literal, base64 encoding, base64+XOR, or a char-code\narray reconstructed at runtime. Some variants instead fetch a mutable, attacker-controlled remote\nJSON/JS list of target JIDs from GitHub or another host at runtime, letting the target list change\nafter installation without a new npm publish. Every sample in the family shares the same underlying\nmechanism (a wrapped/patched socket-connect routine that fires the FOLLOW query some seconds after\nconnect), even though the package name, JID value(s), and obfuscation/delivery method differ per\nfork.\n\nThe malicious action abuses the installer's own authenticated WhatsApp session to gain reach and\nsubscribers for attacker-controlled channels; it does not exfiltrate credentials, establish\npersistence, or execute arbitrary remote code.\n\nAffected package: levvleys (npm), version(s): 2.1.0, 2.0.26, 2.0.25, 2.0.24, 2.0.23, 2.0.22, 2.0.21, 2.0.20, 2.0.19, 2.0.18, 2.0.17, 2.0.16, 2.0.13, 2.0.12, 2.0.11, 2.0.10, 2.0.9, 2.0.8, 2.0.6, 2.0.4.","modified":"2026-09-30T10:32:25.461171398Z","published":"2026-09-30T09:57:36Z","references":[{"type":"ARTICLE","url":"https://www.ox.security/blog/phantomsub-malicious-npm-campaign-secretly-adds-users-to-whatsapp-spam-channels/"}],"affected":[{"package":{"name":"levvleys","ecosystem":"npm","purl":"pkg:npm/levvleys"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["2.1.0","2.0.26","2.0.25","2.0.24","2.0.23","2.0.22","2.0.21","2.0.20","2.0.19","2.0.18","2.0.17","2.0.16","2.0.13","2.0.12","2.0.11","2.0.10","2.0.9","2.0.8","2.0.6","2.0.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/levvleys/MAL-2026-17397.json","iocs":{"urls":["https://raw.githubusercontent.com/LevviCodeID/Levi4than/refs/heads/main/levvleys.json"],"domains":[],"files":[],"ips":[]}}}],"schema_version":"1.9.0","credits":[{"name":"OX Security","type":"FINDER"}]}