plogme is a renamed fork of the Baileys WhatsApp Web library from the same publisher-controlled family as @crysnovax/baileys (MAL-2026-15917), and versions 1.0.0 through 1.0.3 carry the same forced-follow and fingerprint modules. lib/Utils/channel-policy.js (javascript-obfuscator output, identical to the file in MAL-2026-15917) hardcodes the publisher's WhatsApp newsletter channels 120363423670814885@newsletter and 120363402922206865@newsletter and exports followCrysnovaxTrustedChannels(); lib/Socket/socket.js invokes it from the connection.update handler, so the user's own authenticated WhatsApp account silently follows both channels on every successful connection, with no opt-out. lib/Utils/integrity.js hashes hostname, platform, arch, cpu model and Node version into a machine fingerprint and POSTs it with the package identity to https://bailey.crysnovax.link/api/v1/verify on every socket connect. The obfuscated follow module was decoded, not executed.
-= Per source details. Do not edit below this line.=-
The package was found to contain malicious code or consuming dependency that contains malicious code
{
"iocs": {
"domains": [
"bailey.crysnovax.link"
],
"files": [
{
"digests": {
"sha256": "ee0dc4f66c39603e12b014cc09bee260bb80b9bbfe3d2f1428faccf95bebfec3"
},
"note": "javascript-obfuscator-processed forced-follow module, identical to MAL-2026-15917 (digest from 1.0.0 and 1.0.3)",
"paths": [
"lib/Utils/channel-policy.js"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "c55caba2bdf737f29b600fddc87392eab1de8c9f6626afb4225c028b40841814"
},
"note": "machine-fingerprint POST to bailey.crysnovax.link on every connect (digest from 1.0.3)",
"paths": [
"lib/Utils/integrity.js"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "d6ad429de0e0723c2f19e38c197feb28f60e62526bff155a8da26d52353f66c6"
},
"note": "connection.update hook that invokes the forced follow, identical to MAL-2026-15917 (digest from 1.0.0 and 1.0.3)",
"paths": [
"lib/Socket/socket.js"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://bailey.crysnovax.link/api/v1/verify"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020773",
"import_time": "2026-09-30T01:36:50.511717642Z",
"modified_time": "2026-09-30T01:10:08Z",
"sha256": "119fcc6129acfa344451ddc3153a9f5215ec2a2c9650a8cb891efc29e774f5f1",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-020774",
"import_time": "2026-09-30T01:36:50.587204641Z",
"modified_time": "2026-09-30T01:10:18Z",
"sha256": "6bb65c1526d48d46d8cefcbeaa3663739b5575898d0ae337475453f5809ab10f",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-020771",
"import_time": "2026-09-30T01:36:50.371149414Z",
"modified_time": "2026-09-30T01:09:48Z",
"sha256": "910cb874b9df298181240891f01e41aece4a3f674f8de8efe3744b006783256f",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-020770",
"import_time": "2026-09-30T01:36:50.249221071Z",
"modified_time": "2026-09-30T01:09:38Z",
"sha256": "d4d72ac4eb16e8ce1e67583792162e2565f96c0153f07453b8a2f6569a368eab",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "lib/Utils/channel-policy.js",
"sha256": "ee0dc4f66c39603e12b014cc09bee260bb80b9bbfe3d2f1428faccf95bebfec3",
"tlsh": "5a8174a99a411e8113c30bd33a37b4d6f27460ee35c48a4afb306991be9f151f4c6672"
},
{
"path": "lib/Utils/integrity.js",
"sha256": "c55caba2bdf737f29b600fddc87392eab1de8c9f6626afb4225c028b40841814",
"tlsh": "8d32babb16a216252a8385ae875a504b7b1cb4133219a8647c5eb3187fcc4b483f7ff1"
},
{
"path": "engine-requirements.js",
"sha256": "7ce6486b989a6b1c52012e1c9a39e791d034e1a009b1356444e54b65fa772c47",
"tlsh": "6441857859a9033176c2d2aca903a0c5af59b01b3220c97139ff72086fdf8604177377"
}
],
"package_integrity": [
{
"filename": "plogme-1.0.2.tgz",
"hashes": {
"sha1": "d6d4efcfce7c22a11a4e519634848ca8db14b166",
"sha512_sri": "sha512-9W327k/K7FsffFAbvlcJKu3xj52vvKd2MhOf+NQ6yf2E8G3sNZQM/bwovbGtrrwB7LyrIStxEgHjzBf5/pVAJA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/plogme/MAL-2026-16199.json"