Malicious code in @prototypevip/baileys (npm)
The @prototypevip/baileys npm package version 0.0.3 contains malicious code that intercepts incoming WhatsApp messages and, if the bot is not tagged with a specific hardcoded owner string, uses the installer's authenticated WhatsApp session to send an unauthorized Arabic message to the installer's contacts. This behavior is hidden by base64 obfuscation and disrupts normal message handling by throwing an error.
AI Analysis
Technical Summary
@prototypevip/baileys is a fork of the Baileys WhatsApp library. In version 0.0.3, the file lib/Store/prototype-store.js registers a listener on the 'messages.upsert' event that executes on every incoming message. The listener's code is obfuscated using base64 encoding. It checks for an active WhatsApp socket and a hardcoded owner string 'gintoki'. If the bot is not tagged with this owner string, the code sends an Arabic message ('you are no longer authorized to use this bot') through the installer's WhatsApp account to their contacts and then throws a 'Blocked' error to halt message processing. This malicious behavior abuses the installer's authenticated session to propagate attacker-controlled content and disrupts normal operation.
Potential Impact
The malicious code abuses the installer's authenticated WhatsApp session to send attacker-authored messages to the installer's contacts without authorization. This can lead to unauthorized message propagation, potential reputational damage, and denial of service for the bot's message handling. The installer's session is leveraged to broadcast messages that may confuse or alarm contacts. The code also halts normal message processing by throwing an error, disrupting the bot's functionality.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using version 0.0.3 of @prototypevip/baileys. Since the malicious behavior is embedded in the package code, removing or replacing the package with a trusted, clean version is recommended. Monitor for vendor advisories for any updates or official fixes. Until then, do not use this package version in production environments.
Malicious code in @prototypevip/baileys (npm)
Description
The @prototypevip/baileys npm package version 0.0.3 contains malicious code that intercepts incoming WhatsApp messages and, if the bot is not tagged with a specific hardcoded owner string, uses the installer's authenticated WhatsApp session to send an unauthorized Arabic message to the installer's contacts. This behavior is hidden by base64 obfuscation and disrupts normal message handling by throwing an error.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
@prototypevip/baileys is a fork of the Baileys WhatsApp library. In version 0.0.3, the file lib/Store/prototype-store.js registers a listener on the 'messages.upsert' event that executes on every incoming message. The listener's code is obfuscated using base64 encoding. It checks for an active WhatsApp socket and a hardcoded owner string 'gintoki'. If the bot is not tagged with this owner string, the code sends an Arabic message ('you are no longer authorized to use this bot') through the installer's WhatsApp account to their contacts and then throws a 'Blocked' error to halt message processing. This malicious behavior abuses the installer's authenticated session to propagate attacker-controlled content and disrupts normal operation.
Potential Impact
The malicious code abuses the installer's authenticated WhatsApp session to send attacker-authored messages to the installer's contacts without authorization. This can lead to unauthorized message propagation, potential reputational damage, and denial of service for the bot's message handling. The installer's session is leveraged to broadcast messages that may confuse or alarm contacts. The code also halts normal message processing by throwing an error, disrupting the bot's functionality.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using version 0.0.3 of @prototypevip/baileys. Since the malicious behavior is embedded in the package code, removing or replacing the package with a trusted, clean version is recommended. Monitor for vendor advisories for any updates or official fixes. Until then, do not use this package version in production environments.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13480
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7573b5bf8831d539d93a81
Added to database: 08/07/2026, 05:57:09 UTC
Last enriched: 08/07/2026, 08:02:20 UTC
Last updated: 08/07/2026, 08:02:20 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.