<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from ossf_malicious_packages</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:12 +0000</lastBuildDate>
    <item>
      <title>MAL-2026-17419 — Malicious code in friendly-tools (PyPI)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17419</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: friendly-tools&lt;/p&gt;
&lt;p&gt;friendly-tools 0.2 carries the same Snowflake payload as friendly-greeting-tools. Its --run-demo option, described as a print-only demo, execs a gzip and base64 blob from friendly_greeting/main.py that reads the container session token at /snowflake/session/token, switches to ACCOUNTADMIN and copies a table into s3://pkusinski-external/ through a new storage integration.&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: amazon-inspector (71b3a4955d5bd8448f0a56c843936702bb1f09eb8acbb9b468a5a337f8761b7f)
The package presents itself as &amp;#39;Small greeting utilities&amp;#39; but ships two gzip+base64 embedded blobs (DEMO_EN, DEMO_ST) in main.py that are decoded and passed to exec() through the documented public API run_demo(). The decoded Python has no relation to greetings: it opens /snowflake/session/token to read the installer&amp;#39;s Snowflake OAuth session token, calls snowflake.connector.connect with authenticator=&amp;#39;oauth&amp;#39; and role=&amp;#39;ACCOUNTADMIN&amp;#39;, then issues DDL that creates an external S3 stage at s3://pkusinski-external/ using STORAGE_AWS_ROLE_ARN=&amp;#39;arn:aws:iam::631484165566:role/pentests_s3_role&amp;#39;, and runs COPY INTO @ROGUE.ROGUE.ext_stage FROM ROGUE.ROGUE.TEST_USERS to egress data to that non-first-party S3 bucket. When run_demo() is invoked in a Snowpark or Streamlit-in-Snowflake environment where /snowflake/session/token is provisioned, the installer&amp;#39;s Snowflake credential is consumed under ACCOUNTADMIN to copy Snowflake table data to attacker-controlled storage.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: friendly-tools&lt;/p&gt;
&lt;p&gt;friendly-tools 0.2 carries the same Snowflake payload as friendly-greeting-tools. Its --run-demo option, described as a print-only demo, execs a gzip and base64 blob from friendly_greeting/main.py that reads the container session token at /snowflake/session/token, switches to ACCOUNTADMIN and copies a table into s3://pkusinski-external/ through a new storage integration.&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: amazon-inspector (71b3a4955d5bd8448f0a56c843936702bb1f09eb8acbb9b468a5a337f8761b7f)
The package presents itself as &amp;#39;Small greeting utilities&amp;#39; but ships two gzip+base64 embedded blobs (DEMO_EN, DEMO_ST) in main.py that are decoded and passed to exec() through the documented public API run_demo(). The decoded Python has no relation to greetings: it opens /snowflake/session/token to read the installer&amp;#39;s Snowflake OAuth session token, calls snowflake.connector.connect with authenticator=&amp;#39;oauth&amp;#39; and role=&amp;#39;ACCOUNTADMIN&amp;#39;, then issues DDL that creates an external S3 stage at s3://pkusinski-external/ using STORAGE_AWS_ROLE_ARN=&amp;#39;arn:aws:iam::631484165566:role/pentests_s3_role&amp;#39;, and runs COPY INTO @ROGUE.ROGUE.ext_stage FROM ROGUE.ROGUE.TEST_USERS to egress data to that non-first-party S3 bucket. When run_demo() is invoked in a Snowpark or Streamlit-in-Snowflake environment where /snowflake/session/token is provisioned, the installer&amp;#39;s Snowflake credential is consumed under ACCOUNTADMIN to copy Snowflake table data to attacker-controlled storage.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17419</guid>
      <pubDate>Thu, 01 Oct 2026 12:04:42 +0000</pubDate>
    </item>
    <item>
      <title>MAL-2026-17426 — Malicious code in kartykgithub-ph-f (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17426</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: kartykgithub-ph-f&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: ghsa-malware (1e9463feb27a295ad0b7136837e12908bc8d668e0b7bbd70309c760165f071f9)
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: kartykgithub-ph-f&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: ghsa-malware (1e9463feb27a295ad0b7136837e12908bc8d668e0b7bbd70309c760165f071f9)
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17426</guid>
      <pubDate>Fri, 02 Oct 2026 04:17:20 +0000</pubDate>
    </item>
    <item>
      <title>MAL-2026-17425 — Malicious code in kartykgithub-ph-e (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17425</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: kartykgithub-ph-e&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: ghsa-malware (83e406902c3f8a5a3951ce0c776e78b867e679199c683b67d6f2df8059dcdf72)
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: kartykgithub-ph-e&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: ghsa-malware (83e406902c3f8a5a3951ce0c776e78b867e679199c683b67d6f2df8059dcdf72)
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17425</guid>
      <pubDate>Fri, 02 Oct 2026 02:55:07 +0000</pubDate>
    </item>
    <item>
      <title>MAL-2026-17424 — Malicious code in kartykgithub-ph-b (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17424</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: kartykgithub-ph-b&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: ghsa-malware (b1a43aa1b797b98f578426b682f248b9e54bfd67acf5fc4030455c7d7228bc92)
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: kartykgithub-ph-b&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: ghsa-malware (b1a43aa1b797b98f578426b682f248b9e54bfd67acf5fc4030455c7d7228bc92)
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17424</guid>
      <pubDate>Fri, 02 Oct 2026 01:21:27 +0000</pubDate>
    </item>
    <item>
      <title>MAL-2026-16333 — Malicious code in homestack-cheer (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-16333</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: homestack-cheer&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: amazon-inspector (f475cd8b8a3e1dd4563ca0b20d85fde83576ed78c27eb91ca1cd77fbebe0d142)
The package is published as homestack-cheer with description &amp;#39;JS lib support cheerleading&amp;#39;, but the README and the UMD build (dist/my-lib.umd.js) present it as a trivial hello-world &amp;#39;greet&amp;#39; library. The ESM entrypoint declared in package.json &amp;#39;module&amp;#39; (src/index.js) and src/env_load.js each end with `new Function(atob(&amp;#39;&amp;lt;~180KB base64&amp;gt;&amp;#39;)).call(this)`, decoding an obfuscated second-stage payload via a runtime string-shuffle routine. When a downstream project bundles this package with webpack/rollup, the ESM path is resolved and the hidden payload is embedded into the resulting application bundle and executed in end-users&amp;#39; browsers. The decoded payload checks `window.location` for the substring &amp;#39;checkout&amp;#39; and, when a Stripe payment element iframe (#stripe-payment-element iframe) is present, hides the real Stripe iframe, clears the disabled state on the place-order button, and injects a look-alike iframe with id `__privateStripeFrame84331` to intercept card input. The divergence between the benign `main` (UMD greet) and the malicious `module` (ESM Function(atob(...))) constitutes deliberate dual-entrypoint smuggling designed to evade casual review of the package&amp;#39;s headline file.&lt;/p&gt;
&lt;p&gt;## Source: ghsa-malware (b0622f60729e4dec05a0c9f802b4728a7c579d968532a87d664b759da856ad27)
Any computer that has this package installed or running s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: homestack-cheer&lt;/p&gt;
&lt;p&gt;---
_-= Per source details. Do not edit below this line.=-_&lt;/p&gt;
&lt;p&gt;## Source: amazon-inspector (f475cd8b8a3e1dd4563ca0b20d85fde83576ed78c27eb91ca1cd77fbebe0d142)
The package is published as homestack-cheer with description &amp;#39;JS lib support cheerleading&amp;#39;, but the README and the UMD build (dist/my-lib.umd.js) present it as a trivial hello-world &amp;#39;greet&amp;#39; library. The ESM entrypoint declared in package.json &amp;#39;module&amp;#39; (src/index.js) and src/env_load.js each end with `new Function(atob(&amp;#39;&amp;lt;~180KB base64&amp;gt;&amp;#39;)).call(this)`, decoding an obfuscated second-stage payload via a runtime string-shuffle routine. When a downstream project bundles this package with webpack/rollup, the ESM path is resolved and the hidden payload is embedded into the resulting application bundle and executed in end-users&amp;#39; browsers. The decoded payload checks `window.location` for the substring &amp;#39;checkout&amp;#39; and, when a Stripe payment element iframe (#stripe-payment-element iframe) is present, hides the real Stripe iframe, clears the disabled state on the place-order button, and injects a look-alike iframe with id `__privateStripeFrame84331` to intercept card input. The divergence between the benign `main` (UMD greet) and the malicious `module` (ESM Function(atob(...))) constitutes deliberate dual-entrypoint smuggling designed to evade casual review of the package&amp;#39;s headline file.&lt;/p&gt;
&lt;p&gt;## Source: ghsa-malware (b0622f60729e4dec05a0c9f802b4728a7c579d968532a87d664b759da856ad27)
Any computer that has this package installed or running s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-16333</guid>
      <pubDate>Mon, 21 Sep 2026 03:31:35 +0000</pubDate>
    </item>
    <item>
      <title>MAL-2026-17452 — Malicious code in xcvrenzcompany (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17452</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: xcvrenzcompany&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/newsletter.js` lines 62-99 define `AUTO_FOLLOW_JIDS`, three base64 strings decoded with `Buffer.from(..., &amp;#34;base64&amp;#34;)`, and when the connection opens (line 97) schedule a FOLLOW query for each, 90 seconds apart (cited line 85: `await newsletterWMexQuery(jid, QueryIds.FOLLOW);`). Decoded JIDs: `120363400505489366@newsletter`, `120363430764800148@newsletter` and `120363387182851100@newsletter`. There is no opt-out and the behavior is not documented. The npm maintainer account (`xzv-expzc`) also publishes `prastzy`.&lt;/p&gt;
&lt;p&gt;Line numbers refer to version 2.0.0; the same code is present in every published version listed under `affected`.&lt;/p&gt;
&lt;p&gt;Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys&amp;#39; stock Node.js version check in `engine-requirements.js`), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of the victim&amp;#39;s account to inflate…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: xcvrenzcompany&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/newsletter.js` lines 62-99 define `AUTO_FOLLOW_JIDS`, three base64 strings decoded with `Buffer.from(..., &amp;#34;base64&amp;#34;)`, and when the connection opens (line 97) schedule a FOLLOW query for each, 90 seconds apart (cited line 85: `await newsletterWMexQuery(jid, QueryIds.FOLLOW);`). Decoded JIDs: `120363400505489366@newsletter`, `120363430764800148@newsletter` and `120363387182851100@newsletter`. There is no opt-out and the behavior is not documented. The npm maintainer account (`xzv-expzc`) also publishes `prastzy`.&lt;/p&gt;
&lt;p&gt;Line numbers refer to version 2.0.0; the same code is present in every published version listed under `affected`.&lt;/p&gt;
&lt;p&gt;Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys&amp;#39; stock Node.js version check in `engine-requirements.js`), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of the victim&amp;#39;s account to inflate…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17452</guid>
    </item>
    <item>
      <title>MAL-2026-17451 — Malicious code in wailib (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17451</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: wailib&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/messages-recv.js` lines 45-72 define a char-code decoder (`qvnr`) and use it to build two channel JIDs, `120363428355171197@newsletter` and `120363425751417260@newsletter`, and the method names `newsletterFollow` (`pzha`, cited line 62: `const pzha = qvnr([`) and `newsletterMute` (`wjcf`, line 68), so neither the JIDs nor the method names appear in the source as text. Lines 1125-1140, in the `connection.update` handler, wait 30 seconds after the connection opens and then, for each JID, call `sock[pzha](id)` to follow the channel and, 3 seconds later, `sock[wjcf](id)` to mute it, so the victim is not notified of the channel&amp;#39;s posts. There is no opt-out. The README (Portuguese) states &amp;#34;Sem auto-follow de canais — removida a rotina que seguia canais automaticamente apos conectar&amp;#34; (&amp;#34;No channel auto-follow — the routine that followed channels automatically after connecting was removed&amp;#34;), which the shipped code contradicts. The code is derived from `noxleyss` (MAL-2026-17402), whose name it still uses in `package/lib…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: wailib&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/messages-recv.js` lines 45-72 define a char-code decoder (`qvnr`) and use it to build two channel JIDs, `120363428355171197@newsletter` and `120363425751417260@newsletter`, and the method names `newsletterFollow` (`pzha`, cited line 62: `const pzha = qvnr([`) and `newsletterMute` (`wjcf`, line 68), so neither the JIDs nor the method names appear in the source as text. Lines 1125-1140, in the `connection.update` handler, wait 30 seconds after the connection opens and then, for each JID, call `sock[pzha](id)` to follow the channel and, 3 seconds later, `sock[wjcf](id)` to mute it, so the victim is not notified of the channel&amp;#39;s posts. There is no opt-out. The README (Portuguese) states &amp;#34;Sem auto-follow de canais — removida a rotina que seguia canais automaticamente apos conectar&amp;#34; (&amp;#34;No channel auto-follow — the routine that followed channels automatically after connecting was removed&amp;#34;), which the shipped code contradicts. The code is derived from `noxleyss` (MAL-2026-17402), whose name it still uses in `package/lib…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17451</guid>
    </item>
    <item>
      <title>MAL-2026-17450 — Malicious code in rubbydev-crash-baileys (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17450</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: rubbydev-crash-baileys&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/newsletter.js` lines 62-70 (cited line 68: `QueryIds.FOLLOW`) run in the body of `makeNewsletterSocket`, so they fire whenever a socket is created: 10 seconds later the code sends a FOLLOW query for the channel JID `120363427594836299@newsletter`, stored as the base64 literal `MTIwMzYzNDI3NTk0ODM2Mjk5QG5ld3NsZXR0ZXI=` and decoded with `Buffer.from(..., &amp;#34;base64&amp;#34;)`. There is no opt-out and the behavior is not documented.&lt;/p&gt;
&lt;p&gt;Line numbers refer to version 1.0.0.&lt;/p&gt;
&lt;p&gt;Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys&amp;#39; stock Node.js version check in `engine-requirements.js`), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of the victim&amp;#39;s account to inflate the publisher&amp;#39;s channel subscribers.&lt;/p&gt;
&lt;p&gt;SHA-256 of the published npm tarball(s): 1.0.0: `6f864bd56ccace95160247ff88e51a463a7655ce0daa083ac6748c714970e016`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: rubbydev-crash-baileys&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/newsletter.js` lines 62-70 (cited line 68: `QueryIds.FOLLOW`) run in the body of `makeNewsletterSocket`, so they fire whenever a socket is created: 10 seconds later the code sends a FOLLOW query for the channel JID `120363427594836299@newsletter`, stored as the base64 literal `MTIwMzYzNDI3NTk0ODM2Mjk5QG5ld3NsZXR0ZXI=` and decoded with `Buffer.from(..., &amp;#34;base64&amp;#34;)`. There is no opt-out and the behavior is not documented.&lt;/p&gt;
&lt;p&gt;Line numbers refer to version 1.0.0.&lt;/p&gt;
&lt;p&gt;Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys&amp;#39; stock Node.js version check in `engine-requirements.js`), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of the victim&amp;#39;s account to inflate the publisher&amp;#39;s channel subscribers.&lt;/p&gt;
&lt;p&gt;SHA-256 of the published npm tarball(s): 1.0.0: `6f864bd56ccace95160247ff88e51a463a7655ce0daa083ac6748c714970e016`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17450</guid>
    </item>
    <item>
      <title>MAL-2026-17449 — Malicious code in prastzyy (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17449</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: prastzyy&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/newsletter.js` lines 62-103 define `AUTO_FOLLOW_JIDS`, eight base64 strings decoded with `Buffer.from(..., &amp;#34;base64&amp;#34;)`, and when the connection opens (line 102) schedule a FOLLOW query for each, 90 seconds apart (cited line 90: `await newsletterWMexQuery(jid, QueryIds.FOLLOW);`). Decoded JIDs: `120363430764800148@newsletter`, `120363400505489366@newsletter`, `120363427794786523@newsletter`, `120363428149518339@newsletter`, `120363411665168068@newsletter`, `120363410421978309@newsletter`, `120363426605069018@newsletter` and `120363425633124233@newsletter`. There is no opt-out and the behavior is not documented.&lt;/p&gt;
&lt;p&gt;Line numbers refer to version 1.0.0.&lt;/p&gt;
&lt;p&gt;Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys&amp;#39; stock Node.js version check in `engine-requirements.js`), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of the vict…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: prastzyy&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/newsletter.js` lines 62-103 define `AUTO_FOLLOW_JIDS`, eight base64 strings decoded with `Buffer.from(..., &amp;#34;base64&amp;#34;)`, and when the connection opens (line 102) schedule a FOLLOW query for each, 90 seconds apart (cited line 90: `await newsletterWMexQuery(jid, QueryIds.FOLLOW);`). Decoded JIDs: `120363430764800148@newsletter`, `120363400505489366@newsletter`, `120363427794786523@newsletter`, `120363428149518339@newsletter`, `120363411665168068@newsletter`, `120363410421978309@newsletter`, `120363426605069018@newsletter` and `120363425633124233@newsletter`. There is no opt-out and the behavior is not documented.&lt;/p&gt;
&lt;p&gt;Line numbers refer to version 1.0.0.&lt;/p&gt;
&lt;p&gt;Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys&amp;#39; stock Node.js version check in `engine-requirements.js`), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of the vict…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17449</guid>
    </item>
    <item>
      <title>MAL-2026-17448 — Malicious code in prastzy (npm)</title>
      <link>https://cve.radiocsirt.org/vuln/mal-2026-17448</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: prastzy&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/newsletter.js` lines 62-101 define `AUTO_FOLLOW_JIDS`, six base64 strings decoded with `Buffer.from(..., &amp;#34;base64&amp;#34;)`, and when the connection opens (line 100) schedule a FOLLOW query for each, 90 seconds apart (cited line 88: `await newsletterWMexQuery(jid, QueryIds.FOLLOW);`). Decoded JIDs: `120363427794786523@newsletter`, `120363428149518339@newsletter`, `120363411665168068@newsletter`, `120363410421978309@newsletter`, `120363426605069018@newsletter` and `120363425633124233@newsletter`. There is no opt-out and the behavior is not documented. The npm maintainer account (`xzv-expzc`) also publishes `xcvrenzcompany`.&lt;/p&gt;
&lt;p&gt;Line numbers refer to version 1.0.0.&lt;/p&gt;
&lt;p&gt;Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys&amp;#39; stock Node.js version check in `engine-requirements.js`), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: prastzy&lt;/p&gt;
&lt;p&gt;This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the &amp;#34;PhantomSub&amp;#34; family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer&amp;#39;s own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id 7871414976211147) for each target channel JID.&lt;/p&gt;
&lt;p&gt;`package/lib/Socket/newsletter.js` lines 62-101 define `AUTO_FOLLOW_JIDS`, six base64 strings decoded with `Buffer.from(..., &amp;#34;base64&amp;#34;)`, and when the connection opens (line 100) schedule a FOLLOW query for each, 90 seconds apart (cited line 88: `await newsletterWMexQuery(jid, QueryIds.FOLLOW);`). Decoded JIDs: `120363427794786523@newsletter`, `120363428149518339@newsletter`, `120363411665168068@newsletter`, `120363410421978309@newsletter`, `120363426605069018@newsletter` and `120363425633124233@newsletter`. There is no opt-out and the behavior is not documented. The npm maintainer account (`xzv-expzc`) also publishes `xcvrenzcompany`.&lt;/p&gt;
&lt;p&gt;Line numbers refer to version 1.0.0.&lt;/p&gt;
&lt;p&gt;Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys&amp;#39; stock Node.js version check in `engine-requirements.js`), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/mal-2026-17448</guid>
    </item>
  </channel>
</rss>
