VDB
GCVE-110-OSM-2026-12758
GCVE-110-OSM-2026-12758
Advisory PublishedCVSS 9.6/10
This package is a fork of the Baileys WhatsApp library that adds three undocumented channels which use the installer's authenticated WhatsApp session to perform account actions chosen by the author at runtime. In lib/Socket/socket.js around line 334, a base64-encoded URL decodes to https://raw.githubusercontent.com/skyzopedia/Screaper/refs/heads/main/idChannel.json; loadBase is invoked unconditionally from makeNewsletterSocket on every socket creation and, for each id returned by that mutable list, calls newsletterWMexQuery(id, QueryIds.FOLLOW) on the connected account. A second helper (socketConnect, called from validateConnection when the WebSocket opens) reconstructs the URL https://raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json from a numeric char-code array (String.fromCharCode(...)) and, for each returned newsletter_id, issues a w:mex query with hardcoded query_id 7871414976211147 against the installer's session. A third helper, generateMessageV, is exposed on the socket API and, after a 40 second delay, invokes its callback with a hardcoded @newsletter JID obfuscated as a base64 blob XORed with the constant 23, again paired with query_id 7871414976211147. None of these behaviors are described in the README, and both remote lists are runtime-mutable by the author. In addition, package.json declares the cryptographic dependency "@rixxcodex/libsignal": "github:RixxCode/libsignal" with no tag or commit SHA, so npm install resolves whatever HEAD of that repository currently contains and executes it inside the Signal session-encryption path with no integrity check.
ENTRY
lib/index.js (main: ./lib/index.js)
PERSISTENCE
- Startup Persistence in WAProto/index.js: ".profile"
- Startup Persistence in lib/Socket/messages-send.js: ".profile"
- Startup Persistence in lib/Store/make-in-memory-store.js: ".profile"
DESTINATION
- 4 exfil (custom-c2)
- 3 fetched-payload (deobfuscated)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString("base64")"
- Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString("base64")"
- Data Encoding for Exfiltration in lib/Utils/generics.js: "Buffer.from(value?.data || value).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString("base64")"
- Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString("base64")"
- Data Encoding for Exfiltration in lib/gems.js: "Buffer.from(b).toString("base64")"
- Network Request in lib/Utils/generics.js: "fetch('https:"
OBFUSCATION
- Decoded Base64 Content in lib/Utils/messages-media.js
- Decoded Base64 Content in [deobfuscated] lib/Utils/messages-media.js
- IOCs Found in Deobfuscated Code in lib/Socket/socket.js
- Dynamic Base64 Decoding in lib/Socket/dugong.js: "Buffer.from(jpegThumbnail, "base64")"
- Dynamic Base64 Decoding in lib/Socket/socket.js: "Buffer.from(str, "base64")"
- Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, "base64")"
- Dynamic Base64 Decoding in lib/Utils/messages-media.js: "Buffer.from(encoded, "base64")"
- Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, "base64")"
(+10 more)
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
- Rapid Version Publishing
PAYLOAD FILES
lib/Utils/messages-media.js (+ lib/Socket/socket.js, [deobfuscated] lib/Utils/messages-media.js)
## Additional context: PhantomSub campaign
- Remote channel list(s), editable by the operator without publishing a new version (live on 2026-09-24): `hxxps://raw.githubusercontent[.]com/skyzopedia/Screaper/refs/heads/main/idChannel.json` (23 channel(s)), `hxxps://raw.github[.]com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json` (1 channel(s))
- The `idChannel.json` URL is base64-encoded and hidden in media-download code. It decodes to `skyzopedia/Screaper/refs/heads/main/idChannel.json`.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @rixxcodex/baileys | all (affected) | — |
Aliases
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.