Malicious code in santana-baileys (npm)
The santana-baileys npm package, a fork of the Baileys WhatsApp library, contains malicious code that obfuscates a URL pointing to an unauthorized third-party host. This hidden URL is reconstructed from character codes and used within the message sending function, causing messages sent via an authenticated WhatsApp session to be relayed to an attacker-controlled endpoint. This behavior indicates covert exfiltration of messaging data through the compromised package.
AI Analysis
Technical Summary
The santana-baileys package (versions 2.0.2, 2.0.3, and 2.0.4) includes obfuscated code in lib/Socket/messages-send.js that reconstructs a URL (https://fiora.nixel.my.id/) from decimal character codes. This URL is not part of the legitimate Baileys or WhatsApp infrastructure. The code executes during message sending, causing the authenticated WhatsApp session's messages to be sent to this unauthorized third-party host. This covert relay suggests malicious intent to exfiltrate user messaging data through the compromised library.
Potential Impact
Users of the affected santana-baileys versions risk unauthorized disclosure of their WhatsApp messaging data to an attacker-controlled server. This compromises the confidentiality and integrity of communications by relaying messages outside the legitimate WhatsApp infrastructure without user consent or knowledge.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Users should immediately discontinue use of santana-baileys versions 2.0.2, 2.0.3, and 2.0.4. Replace with the official Baileys library or a trusted alternative. Monitor for updates from the package maintainer or vendor advisory for any forthcoming fixes. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in santana-baileys (npm)
Description
The santana-baileys npm package, a fork of the Baileys WhatsApp library, contains malicious code that obfuscates a URL pointing to an unauthorized third-party host. This hidden URL is reconstructed from character codes and used within the message sending function, causing messages sent via an authenticated WhatsApp session to be relayed to an attacker-controlled endpoint. This behavior indicates covert exfiltration of messaging data through the compromised package.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The santana-baileys package (versions 2.0.2, 2.0.3, and 2.0.4) includes obfuscated code in lib/Socket/messages-send.js that reconstructs a URL (https://fiora.nixel.my.id/) from decimal character codes. This URL is not part of the legitimate Baileys or WhatsApp infrastructure. The code executes during message sending, causing the authenticated WhatsApp session's messages to be sent to this unauthorized third-party host. This covert relay suggests malicious intent to exfiltrate user messaging data through the compromised library.
Potential Impact
Users of the affected santana-baileys versions risk unauthorized disclosure of their WhatsApp messaging data to an attacker-controlled server. This compromises the confidentiality and integrity of communications by relaying messages outside the legitimate WhatsApp infrastructure without user consent or knowledge.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Users should immediately discontinue use of santana-baileys versions 2.0.2, 2.0.3, and 2.0.4. Replace with the official Baileys library or a trusted alternative. Monitor for updates from the package maintainer or vendor advisory for any forthcoming fixes. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13456
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7573b5bf8831d539d93b8f
Added to database: 08/07/2026, 05:57:09 UTC
Last enriched: 08/07/2026, 07:33:04 UTC
Last updated: 08/07/2026, 07:33:04 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.