VDB
GCVE-110-OSM-2026-12754
GCVE-110-OSM-2026-12754
Advisory PublishedCVSS 5.4/10
This package is a fork of the Baileys WhatsApp library that quietly makes the developer's authenticated WhatsApp bot session follow newsletter channels chosen by the attacker, without consent. The behavior starts at version 8.0.1 and runs at runtime rather than at install time, so install-time scanning does not see it. The list of channels is fetched from a remote source, so the attacker can change it without publishing a new version. The package also redirects its libsignal dependency to an npm scope controlled by the same attacker. It is part of the wider Baileys follower campaign tracked as PhantomSub.
## Payload 1: delayed newsletter follow
Malicious payload found in: `lib/Socket/newsletter.js`
- Trigger: an immediately invoked function expression runs when the module loads. Present from 8.0.1 (8.0.0 possibly).
- Delay: `setTimeout` of 80 seconds before anything happens.
- Fetch: `fetch('hxxps://raw.githubusercontent[.]com/skyzopedia/Screaper/refs/heads/main/idChannel.json')`, parsed as a JSON list of newsletter IDs.
- Action: for each entry, waits 5 seconds and calls `newsletterWMexQuery(i.id, Types_1.QueryIds.FOLLOW)`. All errors are swallowed in empty `catch` blocks.
- Install phase: the `preinstall` script only checks the Node.js version, so there is no install-time indicator.
## Payload 2: libsignal dependency alias
Malicious payload found in: `package.json`
- `"libsignal": "npm:@skyzopedia/libsignal-node"` redirects the cryptographic dependency to the attacker's scope.
- The package metadata references the upstream author and repository.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @dappaoffc/baileys-mod | all (affected) | — |
Aliases
Browse GCVE Records
3,164 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.