Malicious code in jagproject (npm)
The jagproject npm package contains obfuscated malicious code that exfiltrates session data through a hardcoded third-party endpoint (https://fiora.nixel.my.id/) embedded in the message-send code path. The malicious destination is concealed via char-code obfuscation in lib/Socket/messages-send.js.
- Disclosed
- Last updated
- Blast radius
- All users of the jagproject npm package who send messages through the library's messaging API.
- Ecosystems
- Attack vectors
- Affected entities
- jagprojectBaileys-family WhatsApp library fork containing obfuscated malicious code
The jagproject npm package, a fork of the Baileys WhatsApp library, was found to contain deliberately obfuscated malicious code. The package includes char-code-obfuscated destination strings in lib/Socket/messages-send.js at lines 425 and 436 that decode to the URL https://fiora.nixel.my.id/.
This hardcoded third-party host is reconstructed at runtime rather than appearing as a plain string literal, indicating intentional concealment. The URL is embedded directly in the message-send code path, meaning normal use of the library's messaging API routes caller-owned session data through an author-controlled endpoint.
Obfuscated destinations in a messaging library's send path have no legitimate purpose and match the covert-relay pattern previously observed in other compromised Baileys forks. The malicious code was identified by Amazon Inspector and reported through the OpenSSF malicious-packages project.
Users of jagproject should immediately cease use of the package and audit any session data that may have been transmitted through affected versions.
Indicators of compromise
- Packages
- jagproject
- Domains
- fiora.nixel.my.id
Remediation
- Remove the jagproject package from all projects immediately
- Audit and rotate any WhatsApp session credentials or tokens that may have been exposed
- Switch to the official Baileys library or a verified alternative fork
- Review application logs for any suspicious data exfiltration to fiora.nixel.my.id or related endpoints
- Notify users if their session data may have been compromised through this library
Sources
- GitHub Advisory GHSA-7wx2-h52q-4934 · GitHub Advisory Database
Cite this entry
"Malicious code in jagproject (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 6, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-jagproject-npm-yalkij
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit - containedcritical
Malicious code in checkout-desktop-total (npm)
The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.
npmCompromised package - containedcritical
Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in epic-sso (npm)
The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package