MAL-2026-16199

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/plogme/MAL-2026-16199.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16199
Published
2026-09-08T00:00:00Z
Modified
2026-09-30T01:45:10Z
Summary
Malicious code in plogme (npm)
Details

plogme is a renamed fork of the Baileys WhatsApp Web library from the same publisher-controlled family as @crysnovax/baileys (MAL-2026-15917), and versions 1.0.0 through 1.0.3 carry the same forced-follow and fingerprint modules. lib/Utils/channel-policy.js (javascript-obfuscator output, identical to the file in MAL-2026-15917) hardcodes the publisher's WhatsApp newsletter channels 120363423670814885@newsletter and 120363402922206865@newsletter and exports followCrysnovaxTrustedChannels(); lib/Socket/socket.js invokes it from the connection.update handler, so the user's own authenticated WhatsApp account silently follows both channels on every successful connection, with no opt-out. lib/Utils/integrity.js hashes hostname, platform, arch, cpu model and Node version into a machine fingerprint and POSTs it with the package identity to https://bailey.crysnovax.link/api/v1/verify on every socket connect. The obfuscated follow module was decoded, not executed.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (119fcc6129acfa344451ddc3153a9f5215ec2a2c9650a8cb891efc29e774f5f1)

The package was found to contain malicious code or consuming dependency that contains malicious code

Database specific
{
    "iocs": {
        "domains": [
            "bailey.crysnovax.link"
        ],
        "files": [
            {
                "digests": {
                    "sha256": "ee0dc4f66c39603e12b014cc09bee260bb80b9bbfe3d2f1428faccf95bebfec3"
                },
                "note": "javascript-obfuscator-processed forced-follow module, identical to MAL-2026-15917 (digest from 1.0.0 and 1.0.3)",
                "paths": [
                    "lib/Utils/channel-policy.js"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "c55caba2bdf737f29b600fddc87392eab1de8c9f6626afb4225c028b40841814"
                },
                "note": "machine-fingerprint POST to bailey.crysnovax.link on every connect (digest from 1.0.3)",
                "paths": [
                    "lib/Utils/integrity.js"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "d6ad429de0e0723c2f19e38c197feb28f60e62526bff155a8da26d52353f66c6"
                },
                "note": "connection.update hook that invokes the forced follow, identical to MAL-2026-15917 (digest from 1.0.0 and 1.0.3)",
                "paths": [
                    "lib/Socket/socket.js"
                ],
                "source": "PACKAGE_ARCHIVE"
            }
        ],
        "urls": [
            "https://bailey.crysnovax.link/api/v1/verify"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020773",
            "import_time": "2026-09-30T01:36:50.511717642Z",
            "modified_time": "2026-09-30T01:10:08Z",
            "sha256": "119fcc6129acfa344451ddc3153a9f5215ec2a2c9650a8cb891efc29e774f5f1",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-020774",
            "import_time": "2026-09-30T01:36:50.587204641Z",
            "modified_time": "2026-09-30T01:10:18Z",
            "sha256": "6bb65c1526d48d46d8cefcbeaa3663739b5575898d0ae337475453f5809ab10f",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "id": "IN-MAL-2026-020771",
            "import_time": "2026-09-30T01:36:50.371149414Z",
            "modified_time": "2026-09-30T01:09:48Z",
            "sha256": "910cb874b9df298181240891f01e41aece4a3f674f8de8efe3744b006783256f",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-020770",
            "import_time": "2026-09-30T01:36:50.249221071Z",
            "modified_time": "2026-09-30T01:09:38Z",
            "sha256": "d4d72ac4eb16e8ce1e67583792162e2565f96c0153f07453b8a2f6569a368eab",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / plogme

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "lib/Utils/channel-policy.js",
            "sha256": "ee0dc4f66c39603e12b014cc09bee260bb80b9bbfe3d2f1428faccf95bebfec3",
            "tlsh": "5a8174a99a411e8113c30bd33a37b4d6f27460ee35c48a4afb306991be9f151f4c6672"
        },
        {
            "path": "lib/Utils/integrity.js",
            "sha256": "c55caba2bdf737f29b600fddc87392eab1de8c9f6626afb4225c028b40841814",
            "tlsh": "8d32babb16a216252a8385ae875a504b7b1cb4133219a8647c5eb3187fcc4b483f7ff1"
        },
        {
            "path": "engine-requirements.js",
            "sha256": "7ce6486b989a6b1c52012e1c9a39e791d034e1a009b1356444e54b65fa772c47",
            "tlsh": "6441857859a9033176c2d2aca903a0c5af59b01b3220c97139ff72086fdf8604177377"
        }
    ],
    "package_integrity": [
        {
            "filename": "plogme-1.0.2.tgz",
            "hashes": {
                "sha1": "d6d4efcfce7c22a11a4e519634848ca8db14b166",
                "sha512_sri": "sha512-9W327k/K7FsffFAbvlcJKu3xj52vvKd2MhOf+NQ6yf2E8G3sNZQM/bwovbGtrrwB7LyrIStxEgHjzBf5/pVAJA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/plogme/MAL-2026-16199.json"