MAL-2026-12108
Malicious code in alipclutch-baileys (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ca03288df9bbb08b67462ac23b3727d40e260d84289b5e4db6492f168557d216) The package (a fork/lookalike of the Baileys WhatsApp library) contains a hidden network destination in lib/Socket/messages-send.js. At lines 425 and 436, the destination URL is reconstructed at runtime from a String.fromCharCode(...) numeric array that decodes to https://fiora.nixel.my.id/. Encoding a destination host as a char-code array within the message-send path is an obfuscation technique used to conceal the endpoint from casual source inspection; the decoded host is not part of the WhatsApp/Baileys protocol surface and is not a documented, caller-configured endpoint. Given that this file is on the outgoing-message path of a WhatsApp client library, the injected destination is positioned to receive message-related data (session identifiers, message contents, or authentication material) from the installer's session at runtime.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for alipclutch-baileys (npm). Pin to a known-safe version or switch to an alternative.