VDB
Sign up

MAL-2026-16386

Malicious code in @mikudeveloper/baileys (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d03bf7166a5353a0b22409ebbb724ee53f24394c9ff340df668c970772796e28) This package is a fork of Baileys that declares `libsignal` in `package.json` as `github:tenka-san/libsignal-node` — a git dependency with no commit SHA, tag, or integrity check, resolving to whatever HEAD returns at install time and executing any lifecycle scripts inside it. The referenced GitHub account is unrelated to the upstream WhiskeySockets/libsignal-node maintainer, so its owner controls install-time code on every installer of this package. Separately, `makeNewsletterSocket` schedules a 120-second `setTimeout` after connection that fetches a channel-ID list from a hardcoded, mutable URL (`raw.githubusercontent.com/MikuDevReal/V2.0/refs/heads/main/pepek.json`) and issues `QueryIds.FOLLOW` on each entry using the installer's authenticated WhatsApp session, silently subscribing them to author-selected channels with no disclosure in the README. The remote list is author-mutable, so follow targets can change at any time.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@mikudeveloper/baileys

No fixed version published yet for @mikudeveloper/baileys (npm). Pin to a known-safe version or switch to an alternative.

References