Malicious code in @sahril2nd/baileys (npm)
MAL-2026-16105
Published · Modified
Dependency scanning
Check whether @sahril2nd/baileys is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (a3d2089d9678322dc8adbf5e6e740c29d6720133df3489970652a2100641435e)
This package is a fork of the Baileys WhatsApp library that embeds a hardcoded network destination hidden as a String.fromCharCode(...) decimal-ASCII array inside lib/Socket/messages-send.js. The decoded bytes at lines 425 and 436 reconstruct the URL https://fiora.nixel.my.id/ — a host unrelated to any documented Baileys/WhatsApp infrastructure. The destination is assembled at call-time from a numeric array rather than appearing as a plain-text literal, which is a deliberate concealment technique on the message-send code path where WhatsApp session data and outbound message content are handled. Obfuscated construction of a non-first-party destination inside the messaging pipeline of a WhatsApp client library is the shape of session/message exfiltration to an author-controlled endpoint.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes