MAL-2026-13930

    Dashboard / Malicious Package / MAL-2026-13930

    MAL-2026-13930

    Published: 10 Aug 2026Last Modified: 14 Aug 2026

    Summary: Malicious code in @dreamguyxeon/baileyx (npm)

    Details: npm/@dreamguyxeon/baileyx is a Baileys WhatsApp Web API fork with the same undisclosed remote-controlled consentless newsletter auto-follow as related DGXeon packages. In lib/Socket/newsletter.js, after session setup it waits 120 seconds, fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json, and silently FOLLOWs listed newsletter JIDs. Trigger is runtime (makeNewsletterSocket), not install. It also fetches Baileys version metadata from DGXeon13/dgxeon-soket and aliases libsignal to npm:@dgxeon13/[email protected] (a separate package that patches @whiskeysockets/baileys). Independently corroborated by LPM Firewall's public malicious report for 2.0.0. Related OSV entries: dgxeon-baileys (MAL-2026-2252), baileys-dgxeon (MAL-2025-806). Tarball sha256 for 5.0.0: 0dffc5f0c8fd53b520c26de8788e6eafb1d939070a698e39f9f9853f42e6f7db. Source: amazon-inspector (c1b873d1c35283cbabd9bc82c8bffa55d3151abec85a75522ed8565c93d0546a) This package is a fork of the Baileys WhatsApp library that contains an undocumented runtime hijack of the consumer's authenticated WhatsApp account. In lib/Socket/newsletter.js (lines 102-122), when the consumer creates a WhatsApp socket — the package's main advertised function — a 120-second setTimeout fires, fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json, and for each newsletter ID in that list issues a QueryIds.FOLLOW request under the user's authenticated session. The list is hosted on a mutable `main` branch under the package author's GitHub account, so the author can rotate the targeted channels at any time post-publication without republishing the package. The behavior is not mentioned in the README and is not gated by any user prompt or configuration. The main entrypoint lib/index.js is additionally wrapped in a custom base91 string-table decoder with anti-debugger `debugger` statements and `eval("this")`, concealing the bootstrap edges from casual review. The package also aliases the security-critical `libsignal` dependency to the same author's scope (`npm:@dreamguyxeon/[email protected]`), placing crypto primitives under the same trust boundary as the silent-relay code. Installer harm: any consumer who connects this fork to their WhatsApp account has their identity used to silently follow channels of the author's choosing, with the target list mutable indefinitely.

    Affected packages

    Package

    Name: @dreamguyxeon/baileyx

    Purl: pkg:npm/%40dreamguyxeon/baileyx

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-13930 | CVE-DB