@dreamguyxeon/baileyx@5.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC
OSV ID
MAL-2026-13930
Ecosystem
npm
Summary
This package is a fork of the Baileys WhatsApp library that contains an undocumented runtime hijack of the consumer's authenticated WhatsApp account. In lib/Socket/newsletter.js (lines 102-122), when the consumer creates a WhatsApp socket — the package's main advertised function — a 120-second setTimeout fires, fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json, and for each newsletter ID in that list issues a QueryIds.FOLLOW request under the user's authenticated session. The list is hosted on a mutable main branch under the package author's GitHub account, so the author can rotate the targeted channels at any time post-publication without republishing the package. The behavior is not mentioned in the README and is not gated by any user prompt or configuration. The main entrypoint lib/index.js is additionally wrapped in a custom base91 string-table decoder with anti-debugger debugger statements and eval("this"), concealing the bootstrap edges from casual review. The package also aliases the security-critical libsignal dependency to the same author's scope (npm:@dreamguyxeon/libsignal-node@1.0.0), placing crypto primitives under the same trust boundary as the silent-relay code. Installer harm: any consumer who connects this fork to their WhatsApp account has their identity used to silently follow channels of the author's choosing, with the target list mutable indefinitely.
Source: amazon-inspector (c1b873d1c35283cbabd9bc82c8bffa55d3151abec85a75522ed8565c93d0546a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.