VDB

GCVE-110-OSM-2026-12754

GCVE-110-OSM-2026-12754
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published March 12, 2026
This package is a fork of the Baileys WhatsApp library that quietly makes the developer's authenticated WhatsApp bot session follow newsletter channels chosen by the attacker, without consent. The behavior starts at version 8.0.1 and runs at runtime rather than at install time, so install-time scanning does not see it. The list of channels is fetched from a remote source, so the attacker can change it without publishing a new version. The package also redirects its libsignal dependency to an npm scope controlled by the same attacker. It is part of the wider Baileys follower campaign tracked as PhantomSub. ## Payload 1: delayed newsletter follow Malicious payload found in: `lib/Socket/newsletter.js` - Trigger: an immediately invoked function expression runs when the module loads. Present from 8.0.1 (8.0.0 possibly). - Delay: `setTimeout` of 80 seconds before anything happens. - Fetch: `fetch('hxxps://raw.githubusercontent[.]com/skyzopedia/Screaper/refs/heads/main/idChannel.json')`, parsed as a JSON list of newsletter IDs. - Action: for each entry, waits 5 seconds and calls `newsletterWMexQuery(i.id, Types_1.QueryIds.FOLLOW)`. All errors are swallowed in empty `catch` blocks. - Install phase: the `preinstall` script only checks the Node.js version, so there is no install-time indicator. ## Payload 2: libsignal dependency alias Malicious payload found in: `package.json` - `"libsignal": "npm:@skyzopedia/libsignal-node"` redirects the cryptographic dependency to the attacker's scope. - The package metadata references the upstream author and repository.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@dappaoffc/baileys-modall (affected)—

References

advisory
vendor

Browse GCVE Records

3,164 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›