Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in jagproject (npm)

The jagproject npm package contains obfuscated malicious code that exfiltrates session data through a hardcoded third-party endpoint (https://fiora.nixel.my.id/) embedded in the message-send code path. The malicious destination is concealed via char-code obfuscation in lib/Socket/messages-send.js.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users of the jagproject npm package who send messages through the library's messaging API.
Ecosystems
Attack vectors
Affected entities
  • jagprojectBaileys-family WhatsApp library fork containing obfuscated malicious code

The jagproject npm package, a fork of the Baileys WhatsApp library, was found to contain deliberately obfuscated malicious code. The package includes char-code-obfuscated destination strings in lib/Socket/messages-send.js at lines 425 and 436 that decode to the URL https://fiora.nixel.my.id/.

This hardcoded third-party host is reconstructed at runtime rather than appearing as a plain string literal, indicating intentional concealment. The URL is embedded directly in the message-send code path, meaning normal use of the library's messaging API routes caller-owned session data through an author-controlled endpoint.

Obfuscated destinations in a messaging library's send path have no legitimate purpose and match the covert-relay pattern previously observed in other compromised Baileys forks. The malicious code was identified by Amazon Inspector and reported through the OpenSSF malicious-packages project.

Users of jagproject should immediately cease use of the package and audit any session data that may have been transmitted through affected versions.

Indicators of compromise

Packages
  • jagproject
Domains
  • fiora.nixel.my.id

Remediation

  • Remove the jagproject package from all projects immediately
  • Audit and rotate any WhatsApp session credentials or tokens that may have been exposed
  • Switch to the official Baileys library or a verified alternative fork
  • Review application logs for any suspicious data exfiltration to fiora.nixel.my.id or related endpoints
  • Notify users if their session data may have been compromised through this library

Sources

  1. GitHub Advisory GHSA-7wx2-h52q-4934 · GitHub Advisory Database

Cite this entry

"Malicious code in jagproject (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 6, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-jagproject-npm-yalkij

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit
  2. containedcritical

    Malicious code in checkout-desktop-total (npm)

    The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.

    npmCompromised package
  3. containedcritical

    Malicious code in epic-common (npm)

    The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  4. resolvedcritical

    Malicious code in epic-sso (npm)

    The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package