MAL-2026-15919
Dashboard / Malicious Package / MAL-2026-15919
MAL-2026-15919
Summary: Malicious code in megan-baileys (npm)
Details: megan-baileys is a renamed fork of the Baileys WhatsApp Web library. In lib/Socket/newsletter.js, 90 seconds after makeNewsletterSocket is constructed, a base64-encoded string is decoded to https://files.gifted.co.ke/file/chJids.json, fetched with node-fetch, and every channel id in the response is followed on the user's own authenticated WhatsApp session using the FOLLOW query id 7871414976211147. The follow list is therefore publisher-controlled at runtime, and the URL is hidden from a plaintext search. makeNewsletterSocket is reached from makeWASocket through lib/Socket/messages-send.js, so the behaviour fires for every consumer of the package with no opt-in. The base64 dead-drop and the follow loop are present in all ten published versions (1.0.0 through 1.0.11). No credential or session-key theft was observed, and the dead-drop URL was not requested by pkgwarden. files.gifted.co.ke appears to be a file host used by a wider bot ecosystem and is deliberately not listed as an attacker domain. All versions were fetched from the npm registry and read by hand on 2026-09-03. Same remote-dead-drop shape as MAL-2026-15819 (@mrlegendbot/baileys). Source: amazon-inspector (b6f79c4488100adec664b913cf1be5e70d50ee21eb475e084a6413fb3559ada0) The package's postinstall script walks up from its own install location into the consumer's node_modules directory, removes any existing `@whiskeysockets/baileys` directory there, and writes a replacement `package.json` whose `main`/`exports` point back into megan-baileys' own `lib/index.mjs`. After installation, any code in the installer's project — including transitive dependencies that legitimately declare `@whiskeysockets/baileys` — that calls `require('@whiskeysockets/baileys')` will silently load megan-baileys code instead of the genuine Baileys library published under the @whiskeysockets scope by a different maintainer. This is a dependency-tree hijack executed at install time via a lifecycle hook: the installer's declared dependency graph is mutated to substitute an unrelated author's code for a widely-used scoped package the installer never chose to replace.
References: https://www.npmjs.com/package/megan-baileys, https://osv.dev/vulnerability/MAL-2026-15819, https://osv.dev/vulnerability/MAL-2026-13932, https://pkgwarden.com/incidents/baileys-whatsapp-auto-follow-npm-september-2026/, https://www.npmjs.com/package/megan-baileys/v/1.0.8, https://www.npmjs.com/package/megan-baileys/v/1.0.11
Affected packages
Package
Name: megan-baileys
Purl: pkg:npm/megan-baileys
Affected ranges
Type: N/A
Events:
