VDB
GCVE-110-OSM-2026-2721
GCVE-110-OSM-2026-2721
Advisory PublishedCVSS 5.4/10
This package is part of a campaign that targets Whatsapp users to inflate the threat actors Whatsapp follower numbers. When victims install the package, they silently begin to follow several WhatsApp users and channels automatically.
Payload: lib/Utils/messages-media.js
Secondary files: lib/Utils/generics.js, lib/Utils/chat-utils.js
Key findings:
- IOCs Found in Deobfuscated Code in lib/Utils/generics.js
- Malicious Dependency Detected (OSM) in package.json
- Data Encoding for Exfiltration in lib/Function/Download/tiktok.js: "encodeURIComponent(url"
- Startup Persistence in lib/Function/Download/tiktok.js: ".profile"
- Data Encoding for Exfiltration in lib/Function/Tools/bypass.js: "encodeURIComponent(url)}&siteKey=${encodeURIComponent(siteKey"
The package communicates with these attacker-controlled domains/repositories:
- raw.githubusercontent.com/z4phdev/client (information messages)
- raw.githubusercontent.com/sanndestroyer/destroyerbail (WhatsApp channel IDs to auto-follow)
- raw.githubusercontent.com/z4phdev/baileys (version information)
- (API service reference)
IOCs:
- urls: https://call.whatsapp.com/video/saweitt, https://t.me/saweitt, https://whatsapp.com/channel/0029VaranC0KmCPQCHryFs2C, https://t.me/tskiofc
- domains: shenirapi.shenira9x.me
- domains: raw.githubusercontent.com/z4phdev/client
-domains: raw.githubusercontent.com/sanndestroyer/destroyerbail
- raw.githubusercontent.com/z4phdev/baileys
- payloadFileHash: 7295a6b249f8dd97f121653d4296ac9ff4cb7bdc0c62fd3d70c5edef524ceb04
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @sanndestroyer/baileys | all (affected) | — |
Browse GCVE Records
75,726 records in the GCVE database · Updated August 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.