VDB
KO

MAL-2026-13930

Malicious code in @dreamguyxeon/baileyx (npm)

Details

npm/@dreamguyxeon/baileyx is a Baileys WhatsApp Web API fork with the same undisclosed remote-controlled consentless newsletter auto-follow as related DGXeon packages. In lib/Socket/newsletter.js, after session setup it waits 120 seconds, fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json, and silently FOLLOWs listed newsletter JIDs. Trigger is runtime (makeNewsletterSocket), not install. It also fetches Baileys version metadata from DGXeon13/dgxeon-soket and aliases libsignal to npm:@dgxeon13/libsignal-node@1.0.0 (a separate package that patches @whiskeysockets/baileys). Independently corroborated by LPM Firewall's public malicious report for 2.0.0. Related OSV entries: dgxeon-baileys (MAL-2026-2252), baileys-dgxeon (MAL-2025-806). Tarball sha256 for 5.0.0: 0dffc5f0c8fd53b520c26de8788e6eafb1d939070a698e39f9f9853f42e6f7db.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @dreamguyxeon/baileyx

No fixed version published yet for @dreamguyxeon/baileyx (npm). Pin to a known-safe version or switch to an alternative.

References