VDB

GCVE-110-OSM-2026-12762

GCVE-110-OSM-2026-12762
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 9, 2026
@nexustechpro/baileys is a fork of the WhatsApp library `baileys` in which lib/Socket/chats.js (~270 KB) is heavily obfuscated (obfuscator.io-style rotating string-array decoder, hex-escaped import specifiers such as '\x40\x63\x61\x63\x68\x65\x61\x62\x6c\x65\x2f\x6e\x6f\x64\x65\x2d\x63\x61\x63\x68\x65', integer-arithmetic control flow, unicode identifier names, ~2772-entry string array) while every sibling file in lib/Socket/ (groups.js, messages-recv.js, socket.js, registration.js) remains readable JavaScript and the upstream whiskeysockets/baileys ships this file unobfuscated. The obfuscated module is reachable from the package entry point (lib/index.js) and sits directly in the code path that handles WhatsApp session state (authState credentials, Signal identity keys, noise keys, signed pre-keys). package.json additionally declares `"whatsapp-rust-bridge": "latest"`, a floating unpinned tag on a non-upstream dependency, which allows that dependency's publisher to ship arbitrary code (including install lifecycle scripts) into every installer of this package on any future install with no version pin or integrity check. ENTRY engine-requirements.js (install-hook: node ./engine-requirements.js) - Install Hook Executes Local JS File in package.json PERSISTENCE - Startup Persistence in lib/Socket/messages-send.js: ".profile" - Startup Persistence in lib/Socket/nexus-handler.js: ".profile" - Startup Persistence in lib/Store/make-in-memory-store.js: ".profile" - Startup Persistence in lib/WAUSync/Protocols/USyncBusinessProtocol.js: ".profile" DESTINATION - 1 exfil (custom-c2) - 50 fetched-payload (deobfuscated) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/generics.js: "Buffer.from(value?.data || value).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString('base64')" - Network Request in lib/Socket/nexus-handler.js: "axios.get(" - Network Request in lib/Socket/registration.js: "axios.post(" - Network Request in lib/Utils/generics.js: "fetch('https:" OBFUSCATION - IOCs Found in Deobfuscated Code in lib/Socket/chats.js - Dynamic Base64 Decoding in WAProto/WAProtoCompile.js: "Buffer.from(v, 'base64')" - Dynamic Base64 Decoding in lib/Signal/libsignal.js: "Buffer.from(raw, 'base64')" - Obfuscation: augmented proxied array function replacements in lib/Socket/chats.js - Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, 'base64')" - Dynamic Base64 Decoding in lib/Utils/spam-report-utils.js: "Buffer.from(data, 'base64')" - Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, 'base64')" - Decoded Hex Escape Content in lib/Socket/chats.js (x317) (+13 more) ADDITIONAL FINDINGS - Dynamic Code Execution in lib/Socket/nexus-handler.js: "exec(text)" - Platform Detection with Data Collection in lib/Socket/nexus-handler.js: "JSON.stringify({ response_id: data.responseId || crypto.randomUUID(), sections }..." PAYLOAD FILES lib/Socket/chats.js ## Additional context: PhantomSub campaign - Channel IDs are embedded in the package source (variant not stated in source for this package). - Channel(s) the package promotes (channel ID, source in package): `0029VbBK53XBvvslYeZlBe0V` (NexusBot Official channel, README). OX does not confirm these as auto-follow targets.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@nexustechpro/baileysall (affected)—

References

advisory
vendor

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›