VDB

GCVE-110-OSM-2026-12817

GCVE-110-OSM-2026-12817
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 18, 2026
This package is a fork of the Baileys WhatsApp library that quietly makes the installer's WhatsApp account follow and mute channels controlled by the package author, without consent. It is part of the PhantomSub campaign, which inflates follower counts for channels that sell accounts, bot scripts and similar goods. It does not steal credentials or crypto, but it modifies the victim's account and exposes them to scam content. ## Payload 1: WhatsApp channel auto-follow Malicious payload found in: unknown (not stated in source) - Trigger: code inside the bundled Baileys fork, active while the package is connected to a WhatsApp account. - Behavior: calls the newsletter follow and mute functions for each channel ID it holds, using the connected account. - Remote channel list(s), editable by the operator without publishing a new version (live on 2026-09-24): `hxxps://raw.githubusercontent[.]com/noxXza/data/refs/heads/main/noxleys.json` (1 channel(s)) - Channel(s) the package promotes (channel ID, source in package): `0029VbD8x4q1dAw0XWN7wF0L` (noxleyss info X share code, README of the `noxleyss` twin). OX does not confirm these as auto-follow targets. - Published as a near-identical twin of `noxleyss` (same code under a near-identical name).

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@noxleyss/baileysall (affected)—

References

vendor

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›