VDB

GCVE-110-OSM-2026-12828

GCVE-110-OSM-2026-12828
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 30, 2026
This package is part of a large family (100+ identified as of September 2026) of near-identical forks of the Baileys WhatsApp Web library that inject a covert channel-subscription action into the WhatsApp socket layer. On connect, the injected code issues an authenticated `w:mex` FOLLOW query (query_id 7871414976211147) against one or more attacker-chosen WhatsApp Channel/Newsletter JIDs, using the installer's own authenticated WhatsApp session -- silently subscribing the victim's account to channels it never asked to join. The target JID(s) are hidden from casual source review via one of several obfuscation techniques observed across the family: a plain string literal, base64 encoding, base64+XOR, or a char-code array reconstructed at runtime. Some variants instead fetch a mutable, attacker-controlled remote JSON/JS list of target JIDs from GitHub or another host at runtime, letting the target list change after installation without a new npm publish. Every sample in the family shares the same underlying mechanism (a wrapped/patched socket-connect routine that fires the FOLLOW query some seconds after connect), even though the package name, JID value(s), and obfuscation/delivery method differ per fork. The malicious action abuses the installer's own authenticated WhatsApp session to gain reach and subscribers for attacker-controlled channels; it does not exfiltrate credentials, establish persistence, or execute arbitrary remote code. Affected package: bungoma (npm), version(s): 1.1.0, 1.0.1. ENTRY lib/index.js (main: lib/index.js) PERSISTENCE - Startup Persistence in lib/AIRich/ai-rich/airich.js: ".profile" - Startup Persistence in lib/Socket/messages-send.js: ".profile" EXFIL - Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString('base64')" OBFUSCATION - Dynamic Base64 Decoding in lib/AIRich/ai-rich/airich.js: "Buffer.from(unifiedData, 'base64')" - Dynamic Base64 Decoding in lib/AIRich/ai-rich/toolkit.js: "Buffer.from(media, 'base64')" - Dynamic Base64 Decoding in lib/Signal/Group/group_cipher.js: "Buffer.from(iv, 'base64')" - Dynamic Base64 Decoding in lib/Signal/Group/sender-key-state.js: "Buffer.from(chainKey, 'base64')" - Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, 'base64')" - Dynamic Base64 Decoding in lib/Utils/generics.js: "Buffer.from(val, 'base64')" - Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, 'base64')" - String Array Obfuscation in lib/WABinary/constants.js: "[ '1724', 'profile_picture', '1071', '1314', '1605', '407', '990', '1710', '746'..." (+7 more) ADDITIONAL FINDINGS - Silent Process Execution in lib/AIRich/ai-rich/airich.js: "{ silent: true" - Platform Detection with Data Collection in lib/Buttons/sendInappSignup.js: "JSON.stringify({}) }] // }) // } // // sendInappSignup() does the same iOS-fallb..." - Shell Command Execution in lib/Utils/messages-media.js: "require("child_process")" - Dynamic Code Execution in lib/Utils/rich-messages.js: "exec(line)" - Suspicious TLD Domain in package.json: "https://bwmxmd.co.ke" PAYLOAD FILES lib/Utils/chat-utils.js (+ lib/Utils/messages-media.js, lib/AIRich/ai-rich/airich.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownbungomaall (affected)—

References

advisory
vendor

Browse GCVE Records

3,164 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›