Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in noxleys (npm)

0
High
Published: 08/12/2026 (08/12/2026, 10:31:25 UTC)
Source: GCVE Database
Product: noxleys

Description

The noxleys npm package, a fork of the Baileys WhatsApp library, contains malicious code that automatically follows and mutes WhatsApp channels controlled by the package author without user consent. This behavior is triggered on every WhatsApp connection update when the connection opens, after a 30-second delay, by fetching a mutable list of channel IDs from an author-controlled GitHub URL. The package does not disclose this behavior and uses the installer's authenticated WhatsApp account to perform these actions. No credential theft or environment scraping is reported, but the package effectively grants the author control over the user's WhatsApp interactions. The package versions 1.0.0 through 1.1.6 are affected.

Affected software

npmghsa
noxleys
Affected versions
=1.1.6=1.1.5=1.1.4=1.0.0=1.1.1=1.1.0=1.1.3=1.1.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:41:40 UTC

Technical Analysis

The noxleys npm package integrates an undocumented routine into the WhatsApp connection lifecycle that, upon connection opening, fetches a JSON list of channel IDs from a mutable, author-controlled GitHub raw URL. It then automatically invokes 'newsletterFollow' and 'newsletterMute' on the installer's authenticated WhatsApp account for each channel ID, with randomized delays and shuffling. This behavior is not disclosed in the package documentation and is not opt-in, effectively allowing the author to manipulate the user's WhatsApp account without permission. Additional helper functions fetch data from other mutable author-controlled GitHub URLs but do not execute code or run automatically at install time. There is no evidence of credential theft, environment scraping, or backdoor mechanisms. However, the mutable nature of the channel list means the author can change the followed accounts at any time without releasing a new package version. The package versions affected are 1.0.0, 1.1.0 through 1.1.6.

Potential Impact

The malicious behavior causes the installer's WhatsApp account to automatically follow and mute channels controlled by the package author without user consent, potentially compromising user privacy and trust. Since the channel list is fetched from a mutable branch, the author can dynamically change which channels are followed, maintaining persistent unauthorized control over the user's WhatsApp interactions. Although no credential theft or system compromise is reported, the package effectively manipulates the user's account actions, which could lead to further indirect impacts such as spam or unwanted content exposure. The ghsa-malware source considers any system with this package installed as fully compromised, recommending immediate secret and key rotation and package removal.

Defensive Guidance

Remove the noxleys package immediately from all affected systems. Rotate all secrets and keys stored on the compromised computer from a different, trusted device, as the package author may have gained control over the system's WhatsApp account. Since the malicious behavior relies on fetching data from mutable author-controlled GitHub URLs, avoid using this package or any forks thereof. No official patch or fix is available; the package should be considered malicious and untrusted. Monitor for any unauthorized WhatsApp activity and consider reinstalling WhatsApp or restoring from a clean backup if suspicious behavior persists.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13831
Osv Schema Version
1.7.4
Aliases
["GHSA-rch8-8p8v-23j7"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b44bf8831d539cdcfc2

Added to database: 08/12/2026, 16:11:48 UTC

Last enriched: 08/12/2026, 16:41:40 UTC

Last updated: 08/13/2026, 02:36:29 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses