VDB
GCVE-110-OSM-2026-12797
GCVE-110-OSM-2026-12797
Advisory PublishedCVSS 9.6/10
This package is part of a large family (100+ identified as of September 2026) of near-identical
forks of the Baileys WhatsApp Web library that inject a covert channel-subscription action into
the WhatsApp socket layer. On connect, the injected code issues an authenticated `w:mex` FOLLOW
query (query_id 7871414976211147) against one or more attacker-chosen WhatsApp Channel/Newsletter
JIDs, using the installer's own authenticated WhatsApp session -- silently subscribing the
victim's account to channels it never asked to join.
The target JID(s) are hidden from casual source review via one of several obfuscation techniques
observed across the family: a plain string literal, base64 encoding, base64+XOR, or a char-code
array reconstructed at runtime. Some variants instead fetch a mutable, attacker-controlled remote
JSON/JS list of target JIDs from GitHub or another host at runtime, letting the target list change
after installation without a new npm publish. Every sample in the family shares the same underlying
mechanism (a wrapped/patched socket-connect routine that fires the FOLLOW query some seconds after
connect), even though the package name, JID value(s), and obfuscation/delivery method differ per
fork.
The malicious action abuses the installer's own authenticated WhatsApp session to gain reach and
subscribers for attacker-controlled channels; it does not exfiltrate credentials, establish
persistence, or execute arbitrary remote code.
Affected package: @queenanya/baileys (npm), version(s): 9.10.1, 9.7.3-beta.1, 9.7.2.
ENTRY
engine-requirements.js (install-hook: node ./engine-requirements.js)
- Install Hook Executes Local JS File in package.json
PERSISTENCE
- Startup Persistence in assets/wasm/worker-modules.js: ".profile"
- Startup Persistence in lib/Socket/chats.js: ".profile"
- Startup Persistence in lib/Socket/messages-send.js: ".profile"
- Startup Persistence in lib/addons/message-utils.js: ".profile"
DESTINATION
- 15 exfil (reconstructed, custom-c2)
- 2 c2 (domains)
- 1 fetched-payload (deobfuscated)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in assets/wasm/worker-modules.js: "encodeURIComponent(String(e))}).join("&")),n}l.default=s}),98"
- Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/generics.js: "Buffer.from(value?.data || value).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString('base64')"
- Data Encoding for Exfiltration in lib/addons/message-composer.js: "encodeURIComponent(latexExpr"
- Data Encoding for Exfiltration in lib/addons/rich-response.js: "encodeURIComponent(`\\documentclass{standalone}\\begin{document}\\Large $${expre..."
(+4 more)
OBFUSCATION
- Global Variable Shadowing in lib/Voip/wasm-engine.js: "const module = {"
- Global Variable Shadowing in lib/Voip/worker-bootstrap.js: "const module = {"
- IOCs Found in Deobfuscated Code in lib/Utils/messages.js
- IOCs Found in Deobfuscated Code in lib/Voip/wasm-engine.js
- Obfuscation: function to array replacements in assets/wasm/worker-modules.js
- Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, 'base64')"
- Dynamic Base64 Decoding in lib/Utils/messages.js: "Buffer.from(thumbnailSha256, 'base64')"
- Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, 'base64')"
(+12 more)
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in assets/wasm/worker-modules.js: "https://www.internalfb.com/intern/invariant/2/"
- Dynamic Code Execution in assets/wasm/loader.js: "exec(t)"
- XOR-Encoded String Arrays in assets/wasm/loader.js: "var r=[0,97,115,109,1,0,0,0,1]"
- Platform Detection with Data Collection in lib/Framework/MediaManager.js: "JSON.stringify({ 'sticker-pack-id': `com.queenanya.sticker.${randomBytes(4).toS"
PAYLOAD FILES
assets/wasm/worker-modules.js (+ lib/Voip/wasm-engine.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @queenanya/baileys | 9.10.1 (affected) | — |
Aliases
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.