Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in my-auto-follow (npm)

0
High
Published: 08/10/2026 (08/10/2026, 22:30:00 UTC)
Source: GCVE Database
Product: my-auto-follow

Description

The npm package my-auto-follow is a malicious fork of the Baileys WhatsApp Web API that silently issues follow commands to attacker-controlled WhatsApp newsletter channels without user consent. After establishing a session, it waits 120 seconds, fetches a remote JSON list of WhatsApp newsletter IDs from a mutable GitHub repository controlled by the attacker, and automatically follows each channel ID. This behavior is undocumented, lacks user opt-in, and abuses the authenticated WhatsApp account of any developer using the library. The malicious functionality is triggered at runtime, not during installation, and affects versions 1.0.0 through 1.0.3.

Affected software

npmghsa
my-auto-follow
Affected versions
=1.0.0=1.0.1=1.0.2=1.0.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 18:06:48 UTC

Technical Analysis

my-auto-follow is a Baileys WhatsApp Web API fork that embeds undisclosed, remote-controlled, consentless newsletter auto-follow behavior. Specifically, after a WhatsApp session is established, the library waits 120 seconds and fetches a JSON list of WhatsApp newsletter JIDs from an attacker-controlled GitHub URL. It then silently issues follow commands for each listed channel ID without any user prompt or opt-in. The fetched list is mutable and can be changed at any time by the attacker without republishing the package, enabling dynamic control over which channels are followed. This compromises the social graph of the authenticated WhatsApp account using the library. The malicious behavior is triggered at runtime via the makeNewsletterSocket function and affects versions 1.0.0, 1.0.1, 1.0.2, and 1.0.3. There is no official patch or remediation information available.

Potential Impact

Any developer using my-auto-follow versions 1.0.0 through 1.0.3 to power a WhatsApp bot will have their authenticated WhatsApp account silently issue follow commands to attacker-chosen newsletter channels. This results in unauthorized actions performed in the context of the user's WhatsApp identity, potentially manipulating the user's social graph and exposing them to privacy and reputational risks. The attacker can dynamically control which channels are followed by modifying the remote JSON list, without requiring republishing or user interaction.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using the my-auto-follow package and remove it from their projects. Review dependencies for this package and replace with a trusted alternative. Monitor for updates from the package maintainer or security advisories for remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13932
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7e036abf8831d5398f8ac5

Added to database: 08/13/2026, 17:48:26 UTC

Last enriched: 08/13/2026, 18:06:48 UTC

Last updated: 08/13/2026, 19:11:12 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses