Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
MSC-2026-6382
Published:July 27, 2026
Updated:August 02, 2026
Trojanized fork of the Baileys WhatsApp library. lib/Socket/messages-recv.js:1313-1332 contains char-code-obfuscated (String.fromCharCode) WhatsApp newsletter JIDs (120363418691561888@newsletter, 120363420179178031@newsletter, 120363411139192580@newsletter) which are silently followed and then muted approximately 30 seconds after the victim's WhatsApp session opens, hiding them from the user. lib/Socket/newsletter.js:197-222 adds autoJoinChannels(), which fetches an attacker-updatable channel list from https://raw.githubusercontent.com/noxXza/data/refs/heads/main/noxXza.json and follows/mutes each entry with randomized jitter. Both code blocks are confirmed absent from genuine upstream baileys@7.0.0-rc13. The preinstall hook (engine-requirements.js) is a benign decoy byte-identical to upstream; the payload executes at runtime, not install time. Versions 1.0.0 and 1.1.0 are byte-identical in all payload files, so the entire published version history is malicious.
Do you need more information?
Contact Us
CVSS v4
Base Score:
8.8
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
HIGH
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
8.6
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH
Exploit Maturity
HIGH
Weakness Type (CWE)
Reliance on Insufficiently Trustworthy Component
Embedded Malicious Code
Inclusion of Functionality from Untrusted Control Sphere
Hidden Functionality