MAL-2026-13930
Malicious code in @dreamguyxeon/baileyx (npm)
Details
npm/@dreamguyxeon/baileyx is a Baileys WhatsApp Web API fork with the same undisclosed remote-controlled consentless newsletter auto-follow as related DGXeon packages. In lib/Socket/newsletter.js, after session setup it waits 120 seconds, fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json, and silently FOLLOWs listed newsletter JIDs. Trigger is runtime (makeNewsletterSocket), not install. It also fetches Baileys version metadata from DGXeon13/dgxeon-soket and aliases libsignal to npm:@dgxeon13/libsignal-node@1.0.0 (a separate package that patches @whiskeysockets/baileys). Independently corroborated by LPM Firewall's public malicious report for 2.0.0. Related OSV entries: dgxeon-baileys (MAL-2026-2252), baileys-dgxeon (MAL-2025-806). Tarball sha256 for 5.0.0: 0dffc5f0c8fd53b520c26de8788e6eafb1d939070a698e39f9f9853f42e6f7db.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @dreamguyxeon/baileyx (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/@dreamguyxeon/baileyx [PACKAGE]
- https://osv.dev/vulnerability/MAL-2026-2252 [ADVISORY]
- https://osv.dev/vulnerability/MAL-2025-806 [ADVISORY]
- https://firewall.lpm.dev/npm/@dreamguyxeon/baileyx/v/2.0.0 [WEB]
- https://safedep.io/malicious-baileys-npm-whatsapp-campaign/ [WEB]