目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@dreamguyxeon/baileyx

MAL-2026-13930
2026-08-14 14:53:27
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @dreamguyxeon/baileyx (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
431
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.0archivedVIP 下载
2.0.0archivedVIP 下载
3.0.0archivedVIP 下载
4.0.0archivedVIP 下载
5.0.0archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npm@dreamguyxeon/baileyx1.0.0
npm@dreamguyxeon/baileyx2.0.0
npm@dreamguyxeon/baileyx3.0.0
npm@dreamguyxeon/baileyx4.0.0
npm@dreamguyxeon/baileyx5.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-13930","published":"2026-08-10T22:30:00Z","modified":"2026-08-14T14:53:26.957327088Z","summary":"Malicious code in @dreamguyxeon/baileyx (npm)","details":"npm/@dreamguyxeon/baileyx is a Baileys WhatsApp Web API fork with the same undisclosed remote-controlled consentless newsletter auto-follow as related DGXeon packages. In lib/Socket/newsletter.js, after session setup it waits 120 seconds, fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json, and silently FOLLOWs listed newsletter JIDs. Trigger is runtime (makeNewsletterSocket), not install. It also fetches Baileys version metadata from DGXeon13/dgxeon-soket and aliases libsignal to npm:@dgxeon13/libsignal-node@1.0.0 (a separate package that patches @whiskeysockets/baileys). Independently corroborated by LPM Firewall's public malicious report for 2.0.0. Related OSV entries: dgxeon-baileys (MAL-2026-2252), baileys-dgxeon (MAL-2025-806). Tarball sha256 for 5.0.0: 0dffc5f0c8fd53b520c26de8788e6eafb1d939070a698e39f9f9853f42e6f7db.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c1b873d1c35283cbabd9bc82c8bffa55d3151abec85a75522ed8565c93d0546a)\nThis package is a fork of the Baileys WhatsApp library that contains an undocumented runtime hijack of the consumer's authenticated WhatsApp account. In lib/Socket/newsletter.js (lines 102-122), when the consumer creates a WhatsApp socket — the package's main advertised function — a 120-second setTimeout fires, fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json, and for each newsletter ID in that list issues a QueryIds.FOLLOW request under the user's authenticated session. The list is hosted on a mutable `main` branch under the package author's GitHub account, so the author can rotate the targeted channels at any time post-publication without republishing the package. The behavior is not mentioned in the README and is not gated by any user prompt or configuration. The main entrypoint lib/index.js is additionally wrapped in a custom base91 string-table decoder with anti-debugger `debugger` statements and `eval(\"this\")`, concealing the bootstrap edges from casual review. The package also aliases the security-critical `libsignal` dependency to the same author's scope (`npm:@dreamguyxeon/libsignal-node@1.0.0`), placing crypto primitives under the same trust boundary as the silent-relay code. Installer harm: any consumer who connects this fork to their WhatsApp account has their identity used to silently follow channels of the author's choosing, with the target list mutable indefinitely.\n","affected":[{"package":{"name":"@dreamguyxeon/baileyx","ecosystem":"npm"},"versions":["1.0.0","2.0.0","3.0.0","4.0.0","5.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/Socket/newsletter.js","sha256":"d46c64f770bf6f1d7220deb9c9d38e842ba022b8cd95cda654705ba8297e9abb","tlsh":"c452965665fa5aa517a37054e67fb0e0b320f243782598673f8cd4020f4a1dde8b3bd8"},{"path":"lib/index.js","sha256":"806b72da4e0047e5ee91e70676f14b1beea846996f6b45fe263a5963ef994c1a","tlsh":"5e1352c4ffcc7dbec1d01e731077055effa91f400adb9a40a2e16dd0ab9ab4651aa918"},{"path":"package.json","sha256":"d7e464dba8b1c3a596ae06af6e6f1864cc39a7d71ceb7e198bfcd891d05d1e88","tlsh":"ff51ec25cc5cceb314c636e969ba0102907842534d95fc2c336c4bac4f5e25f72b9b2e"}],"package_integrity":[{"filename":"baileyx-1.0.0.tgz","hashes":{"sha1":"6cf0315ebd8912eb1f1d0bd95d662f353f5fd544","sha512_sri":"sha512-XfvM96uEUGK4anRfSTsqV3Q6DfNXUwQOzVlO/8wvjfRTrEgEgvsunFnUkZMf+t8EB/6KUHXPf9mOzSzIWGXEgw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dreamguyxeon/baileyx"},{"type":"ADVISORY","url":"https://osv.dev/vulnerability/MAL-2026-2252"},{"type":"ADVISORY","url":"https://osv.dev/vulnerability/MAL-2025-806"},{"type":"WEB","url":"https://firewall.lpm.dev/npm/@dreamguyxeon/baileyx/v/2.0.0"},{"type":"WEB","url":"https://safedep.io/malicious-baileys-npm-whatsapp-campaign/"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dreamguyxeon/baileyx/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dreamguyxeon/baileyx/v/3.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dreamguyxeon/baileyx/v/2.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dreamguyxeon/baileyx/v/4.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dreamguyxeon/baileyx/v/5.0.0"}],"database_specific":{"iocs":{"urls":["https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json","https://raw.githubusercontent.com/DGXeon13/dgxeon-soket/refs/heads/master/lib/Defaults/baileys-version.json"]},"malicious-packages-origins":[{"id":"IN-MAL-2026-017624","import_time":"2026-08-13T15:26:42.818834673Z","modified_time":"2026-08-13T14:58:19Z","sha256":"c1b873d1c35283cbabd9bc82c8bffa55d3151abec85a75522ed8565c93d0546a","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-017795","import_time":"2026-08-14T14:51:39.063994671Z","modified_time":"2026-08-14T14:37:23Z","sha256":"7ea8f669b9d0f75975bc9b1dd420bbaaade523baf2ac1bd4bc335e6007e10aa4","source":"amazon-inspector","versions":["3.0.0"]},{"id":"IN-MAL-2026-017800","import_time":"2026-08-14T14:51:39.399706035Z","modified_time":"2026-08-14T14:38:18Z","sha256":"9c19da8d5ae5dc169d9d584a1751cbc82ff809bf5d0866786805124a6993ecaa","source":"amazon-inspector","versions":["2.0.0"]},{"id":"IN-MAL-2026-017791","import_time":"2026-08-14T14:51:38.811454662Z","modified_time":"2026-08-14T14:36:44Z","sha256":"a033f5d103d84f240ca1f414b8906b3fa9f5d734e475ae0855cb4940c0875575","source":"amazon-inspector","versions":["4.0.0"]},{"id":"IN-MAL-2026-017788","import_time":"2026-08-14T14:51:38.621336442Z","modified_time":"2026-08-14T14:36:20Z","sha256":"a40a1f6133c242f2ddfbdfa05b03e50ec3f9995e0de10d3dcd6f75343b5924c9","source":"amazon-inspector","versions":["5.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"pkgwarden","contact":["https://pkgwarden.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0