VDB

GCVE-110-OSM-2026-2721

GCVE-110-OSM-2026-2721
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published April 19, 2026
This package is part of a campaign that targets Whatsapp users to inflate the threat actors Whatsapp follower numbers. When victims install the package, they silently begin to follow several WhatsApp users and channels automatically. Payload: lib/Utils/messages-media.js Secondary files: lib/Utils/generics.js, lib/Utils/chat-utils.js Key findings: - IOCs Found in Deobfuscated Code in lib/Utils/generics.js - Malicious Dependency Detected (OSM) in package.json - Data Encoding for Exfiltration in lib/Function/Download/tiktok.js: "encodeURIComponent(url" - Startup Persistence in lib/Function/Download/tiktok.js: ".profile" - Data Encoding for Exfiltration in lib/Function/Tools/bypass.js: "encodeURIComponent(url)}&siteKey=${encodeURIComponent(siteKey" The package communicates with these attacker-controlled domains/repositories: - raw.githubusercontent.com/z4phdev/client (information messages) - raw.githubusercontent.com/sanndestroyer/destroyerbail (WhatsApp channel IDs to auto-follow) - raw.githubusercontent.com/z4phdev/baileys (version information) - (API service reference) IOCs: - urls: https://call.whatsapp.com/video/saweitt, https://t.me/saweitt, https://whatsapp.com/channel/0029VaranC0KmCPQCHryFs2C, https://t.me/tskiofc - domains: shenirapi.shenira9x.me - domains: raw.githubusercontent.com/z4phdev/client -domains: raw.githubusercontent.com/sanndestroyer/destroyerbail - raw.githubusercontent.com/z4phdev/baileys - payloadFileHash: 7295a6b249f8dd97f121653d4296ac9ff4cb7bdc0c62fd3d70c5edef524ceb04

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@sanndestroyer/baileysall (affected)

Browse GCVE Records

75,726 records in the GCVE database · Updated August 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›