VDB
KO

MAL-2026-13482

Malicious code in diezyclutch-baileys (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b034105b4e65e2ff38eef557d7b480758070d1122aa6338a6873a9ee76f9111a) diezyclutch-baileys is a fork of the Baileys WhatsApp library. In lib/Socket/messages-send.js the code constructs a network destination from a String.fromCharCode(...) array that decodes to https://fiora.nixel.my.id/ and issues outbound requests to that host from the message-sending path. Reconstructing the destination URL from a decimal char-code array is deliberate obfuscation of the exfil endpoint; the host is not part of Baileys' documented WhatsApp/Signal protocol traffic and is not a caller-configurable option. This is the canonical shape of a covertly injected exfiltration channel in a WhatsApp-session library, whose messages-send path handles session-authenticated data.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / diezyclutch-baileys

No fixed version published yet for diezyclutch-baileys (npm). Pin to a known-safe version or switch to an alternative.

References