MSC-2026-6382
Published:July 27, 2026
Updated:August 02, 2026
Trojanized fork of the Baileys WhatsApp library. lib/Socket/messages-recv.js:1313-1332 contains char-code-obfuscated (String.fromCharCode) WhatsApp newsletter JIDs (120363418691561888@newsletter, 120363420179178031@newsletter, 120363411139192580@newsletter) which are silently followed and then muted approximately 30 seconds after the victim's WhatsApp session opens, hiding them from the user. lib/Socket/newsletter.js:197-222 adds autoJoinChannels(), which fetches an attacker-updatable channel list from https://raw.githubusercontent.com/noxXza/data/refs/heads/main/noxXza.json and follows/mutes each entry with randomized jitter. Both code blocks are confirmed absent from genuine upstream baileys@7.0.0-rc13. The preinstall hook (engine-requirements.js) is a benign decoy byte-identical to upstream; the payload executes at runtime, not install time. Versions 1.0.0 and 1.1.0 are byte-identical in all payload files, so the entire published version history is malicious.
Related Resources (1)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.8
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
HIGH
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
8.6
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH
Exploit Maturity
HIGH