Skip to content
Malicious NPM Packages Exploit Baileys Forks for WhatsApp Abuse

Malicious NPM Packages Exploit Baileys Forks for WhatsApp Abuse

First seen 28 Sep 2026, 16:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 16:08 UTC
  • •82 malicious Baileys packages identified, affecting WhatsApp accounts.
  • •Attackers exploit trust in NPM forks for non-consensual actions.
  • •Runtime analysis is crucial for detecting this type of supply chain abuse.

A campaign involving malicious forks of the Baileys NPM package exploits WhatsApp accounts by forcing them to follow attacker-controlled channels and injecting advertising URLs into sent media. The campaign has identified 82 confirmed malicious packages built on Baileys across 375 versions, alongside 15 impersonators of the libsignal-node library. Attackers utilize silent follow mechanisms and non-consensual messaging to manipulate user accounts without credential theft. Continuous monitoring has revealed over 4,250 package names associated with Baileys, with the malicious campaign still expanding. Detection methods emphasize the need for runtime-aware supply chain controls, as the malicious behavior executes post-installation, hidden within legitimate code. Current defenses must focus on behavior-aware analysis rather than solely relying on install-time scanning. The situation remains dynamic, with further investigations ongoing.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
Malicious Baileys campaign disclosed
Reports confirmed the existence of 82 malicious packages targeting WhatsApp users through Baileys forks.
safedep.io
2026-09-28
Xygeni's MEW detects malicious behavior
Xygeni's Malware Early Warning system identified malicious patterns in Baileys forks, emphasizing the need for runtime analysis.
xygeni.io

More articles in this cluster (2)