Critical

Malicious WhatsApp Skill with Base64 Encoded Reverse Shell Installation

A skill package that claims to add WhatsApp automation actually contains a hidden installation step that downloads and runs attacker code. The malicious command is disguised using base64 encoding so it isn't obvious at a glance, and it connects back to an attacker-controlled server.

How the attack works

An attacker publishes or distributes a skill/plugin that presents itself as a legitimate WhatsApp automation tool. Buried in its installation instructions is a command that decodes a base64 string and executes it as a shell command. That decoded command fetches and runs a reverse shell payload from a remote IP address, giving the attacker interactive control over the machine that installed the skill. Because the payload is base64-encoded, it does not look like a plain shell command or URL when someone skims the skill's source or instructions.

Netzilo detection

Netzilo reports this behaviour when it is observed.

Signature ID
9260ad6e-d542-41fe-946d-8b61e213e8b5
Severity
Critical

Why it matters

If an agent or user installs the skill, the attacker gains a remote shell on the host running it, which can lead to full compromise of that system, theft of credentials or data, and a foothold for further attacks on connected agents or infrastructure.

What you can do

  • Review any skill's full installation instructions before running them, especially commands piped to a shell or decoding base64 strings.
  • Block or flag installation steps that combine base64 decoding with direct execution (e.g. `base64 -d | sh`).
  • Restrict outbound connections from agent hosts to known, allow-listed destinations so callbacks to unknown IPs are blocked or logged.
  • Only install skills from vetted, verified sources and check for signed packages or reproducible builds where possible.

Known benign look-alikes

  • Legitimate package managers using HTTPS endpoints with verification
  • Documentation examples that quote malicious commands without execution context
  • Security training materials describing attack patterns as text

References

Related threats