MAL-2026-15919

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/megan-baileys/MAL-2026-15919.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-15919
Published
2026-09-03T18:09:54Z
Modified
2026-09-04T06:15:05.333911944Z
Summary
Malicious code in megan-baileys (npm)
Details

megan-baileys is a renamed fork of the Baileys WhatsApp Web library. In lib/Socket/newsletter.js, 90 seconds after makeNewsletterSocket is constructed, a base64-encoded string is decoded to https://files.gifted.co.ke/file/chJids.json, fetched with node-fetch, and every channel id in the response is followed on the user's own authenticated WhatsApp session using the FOLLOW query id 7871414976211147. The follow list is therefore publisher-controlled at runtime, and the URL is hidden from a plaintext search. makeNewsletterSocket is reached from makeWASocket through lib/Socket/messages-send.js, so the behaviour fires for every consumer of the package with no opt-in. The base64 dead-drop and the follow loop are present in all ten published versions (1.0.0 through 1.0.11). No credential or session-key theft was observed, and the dead-drop URL was not requested by pkgwarden. files.gifted.co.ke appears to be a file host used by a wider bot ecosystem and is deliberately not listed as an attacker domain. All versions were fetched from the npm registry and read by hand on 2026-09-03. Same remote-dead-drop shape as MAL-2026-15819 (@mrlegendbot/baileys).

Database specific
{
    "iocs": {
        "urls": [
            "https://files.gifted.co.ke/file/chJids.json"
        ],
        "files": [
            {
                "source": "PACKAGE_ARCHIVE",
                "paths": [
                    "lib/Socket/newsletter.js"
                ],
                "note": "base64-hidden dead-drop URL and forced follow loop (digest from 1.0.11)",
                "digests": {
                    "sha256": "c5fd93d838a136067d6bc89d5df6e2433cfa693ff13fe5fe44dc8bcd3a3c5180"
                }
            }
        ]
    }
}
References
Credits

Affected packages

npm / megan-baileys

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.0.11

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/megan-baileys/MAL-2026-15919.json"