MAL-2026-16105

    Dashboard / Malicious Package / MAL-2026-16105

    MAL-2026-16105

    Published: 9 Sept 2026Last Modified: 9 Sept 2026

    Summary: Malicious code in @sahril2nd/baileys (npm)

    Details: Source: amazon-inspector (a3d2089d9678322dc8adbf5e6e740c29d6720133df3489970652a2100641435e) This package is a fork of the Baileys WhatsApp library that embeds a hardcoded network destination hidden as a String.fromCharCode(...) decimal-ASCII array inside lib/Socket/messages-send.js. The decoded bytes at lines 425 and 436 reconstruct the URL https://fiora.nixel.my.id/ — a host unrelated to any documented Baileys/WhatsApp infrastructure. The destination is assembled at call-time from a numeric array rather than appearing as a plain-text literal, which is a deliberate concealment technique on the message-send code path where WhatsApp session data and outbound message content are handled. Obfuscated construction of a non-first-party destination inside the messaging pipeline of a WhatsApp client library is the shape of session/message exfiltration to an author-controlled endpoint.

    Affected packages

    Package

    Name: @sahril2nd/baileys

    Purl: pkg:npm/%40sahril2nd/baileys

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.21