MAL-2026-16105
Malicious code in @sahril2nd/baileys (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (a3d2089d9678322dc8adbf5e6e740c29d6720133df3489970652a2100641435e) This package is a fork of the Baileys WhatsApp library that embeds a hardcoded network destination hidden as a String.fromCharCode(...) decimal-ASCII array inside lib/Socket/messages-send.js. The decoded bytes at lines 425 and 436 reconstruct the URL https://fiora.nixel.my.id/ — a host unrelated to any documented Baileys/WhatsApp infrastructure. The destination is assembled at call-time from a numeric array rather than appearing as a plain-text literal, which is a deliberate concealment technique on the message-send code path where WhatsApp session data and outbound message content are handled. Obfuscated construction of a non-first-party destination inside the messaging pipeline of a WhatsApp client library is the shape of session/message exfiltration to an author-controlled endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @sahril2nd/baileys (npm). Pin to a known-safe version or switch to an alternative.