Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

itsmeeaizat-baileynpm

itsmeeaizat-bailey is a confirmed malicious npm package (MAL-2026-17311) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.3, 1.0.4, 1.0.5). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in itsmeeaizat-bailey (npm)

MAL-2026-17311
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall itsmeeaizat-bailey

What this malware does

package.json declares the libsignal dependency as git+https://github.com/whiskeysockets/libsignal-node with no tag, no commit SHA, and no integrity constraint. On npm install, this resolves to whatever the default branch HEAD currently points at and executes any lifecycle scripts inside that fetched tree on the installer's machine — the delivered bytes and their behavior can change at any moment without a version bump to this package. Separately, the default socket factory in this Baileys fork wires an on-connection hook that, roughly 90 seconds after the installer's WhatsApp session opens, silently issues a FOLLOW MEX query for the hardcoded newsletter JID 120363400911374213@newsletter, which is owned by the package author. The behavior is not documented in the README and is only disableable via an undocumented autoFollowNewsletterOnConnect:false option, so the installer's authenticated WhatsApp identity is used to perform a social reach-padding action they did not opt into. No credential theft, exfiltration to an author endpoint, backdoor, or install-time destructive action is present in the shipped code.

Malicious versions

3 flagged
1.0.31.0.41.0.5

Indicators of compromise (SHA-256)

aa89fc4b6ac9b670004406f8d95eee96891afc83758b023cf6fdeb23c70abcdc
d33df45ab827c11b7a27184ffdfe922765eaafb919cd6908cdc715453cadbeac
e87b4292727088efa5df8326a5f868b2c6bb3ae66ee15cecc18f2fa899296075

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for itsmeeaizat-bailey (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging itsmeeaizat-bailey across your stack and pipelines.

  2. If you installed it — respond

    itsmeeaizat-bailey is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If itsmeeaizat-bailey was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks itsmeeaizat-bailey before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. itsmeeaizat-bailey on npm has been identified as a malicious package (versions 1.0.3, 1.0.4, 1.0.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-020789IN-MAL-2026-020788IN-MAL-2026-020792

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks itsmeeaizat-bailey-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

itsmeeaizat-bailey (npm) malicious package — MAL-2026-17311 | O3 Security