🛡️ MAL-2026-12108 — alipclutch-baileys
Description
Malicious code in alipclutch-baileys (npm)
Source: amazon-inspector
This package is a fork of the Baileys WhatsApp library. In lib/Socket/messages-send.js at lines 425 and 436, code uses String.fromCharCode(...) with a decimal-byte array that decodes to the hardcoded host https://fiora.nixel.my.id/ and issues network requests to it from within the message-send path. The destination is obfuscated (reconstructed from a char-code array rather than appearing as a plain URL literal) and is unrelated to WhatsApp's own infrastructure, so on normal use of the send API caller-side message data is diverted to a third-party endpoint controlled by the package author. The obfuscation of the destination, its placement inside the core send path of a WhatsApp automation library, and the lack of any documented purpose for that host are consistent with covert exfiltration/relay of message traffic using the installer's authenticated session.
Affected software
MAL-2026-12108 is recorded against 1 package.
- alipclutch-baileys
Timeline and source
Published on 5 August 2026 and last revised on 6 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| alipclutch-baileys | — | — |
References
Free Vulnerability Check
Is your site affected by MAL-2026-12108?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12108 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.