# CypherX: a WhatsApp bot on Baileys, deployed on Heroku or Docker

> A Node.js WhatsApp bot whose README is two buttons and three pair servers, with the substance in its dependency list: Baileys fork, ffmpeg, DALL-E, PDF generation and a SQLite store.

**Dark-Xploit/CypherX** — 𝙏𝙃𝙀 𝙊𝙁𝙁𝙄𝘾𝙄𝘼𝙇 𝘾𝙔𝙋𝙃𝙀𝙍 𝙓 𝙍𝙀𝙋𝙊𝙎𝙄𝙏𝙊𝙍𝙔.

- Repository: https://github.com/Dark-Xploit/CypherX
- Website: https://www.cypherx.space
- Stars: 2,940 · Forks: 7,797
- Language: Dockerfile
- License: not declared
- Published: 2026-10-06 · Updated: 2026-10-06 · Language: en
- Canonical page: https://hysenlabs.com/projects/dark-xploit-cypherx

## The README is two buttons and a list of pairing servers

There is no documentation. The README is a banner image, a badge, a fork button with a 100000 counter, and a row of server links under a heading that reads session ID and deployments. Three of those links are labelled Server 1, Server 2 and Server 3 on pairing subdomains, and three are labelled offline, which tells you the author hosts a few pairing endpoints centrally and that some of them are currently dead.

The deployment story is one click. The README links a Heroku deploy button pointed at the repository with a template parameter, so forking and deploying is the intended first step for anyone who finds the project. There is a Heroku-specific release fix in version 2.0.4 that addresses the WhatsApp session handling on Heroku and a missing ffmpeg package on that platform, which is the tell that a real share of the user base runs it there.

The homepage is at cypherx.space, and the pairing servers sit on a cypherxbot.space subdomain. For a project with 2,940 stars and 7,797 forks, that fork count is the notable number, several times the star count, which is what you would expect when the documented install path is to press the fork button yourself.

## The WhatsApp library is a pinned fork, which is the whole architecture

The single most important line in `package.json` is the WhatsApp dependency, and it is not the upstream package. It resolves as `@whiskeysockets/baileys` but points at an npm alias for `@tristancage/baileys` at version 6.7.4.

```json
"@whiskeysockets/baileys": "npm:@tristancage/baileys@6.7.4"
```

That detail explains almost everything else about the project. Baileys is an unofficial WhatsApp library that speaks the same protocol as the WhatsApp web client, which means a bot built on it is not an official bot at all: it logs in as a device, the way a linked phone would. A fork pinned to a specific version means the author has patched something the upstream project does not, or needed stability that upstream would not commit to, and you inherit both the patch and the pinning.

The package declares Node greater than or equal to 20 and below 25, and an `allowScripts` block listing which dependencies are permitted to run install scripts. That block is not decoration: `better-sqlite3`, `sqlite3`, `protobufjs` and `core-js` all need native compilation or postinstall work, and listing them explicitly means the project's installer is deliberate about which packages get to execute code at install time. It is a small sign of hygiene in a codebase that otherwise markets itself heavily.

## Reading the dependency list as a feature list

With no prose documentation, the dependencies do the explaining. Media is handled by `fluent-ffmpeg` for video work, `jimp` for image manipulation, and `adm-zip` with `jspdf` for archive and PDF output.

The AI features are named directly. `@google/genai` is the Google GenAI SDK, and the release notes for version 2.0.3 say the `.dalle` and `.generate` commands now produce actual DALL-E images after the AI services had been broken. `google-tts-api` is there for text to speech, and `mathjs` suggests a calculator command, `moment-timezone` handles scheduled messages, and `node-cache` and `node-webpmux` point at caching and multi-device media handling.

There is a long tail of utility packages that describe the command set: `chalk` and `figlet` for the console banner, `lolcatjs` for coloured output, `cheerio` for scraping, `axios` and `node-fetch` for HTTP, `awesome-phonenumber` for number parsing, `acrcloud` for audio fingerprinting, and `ab-downloader` for media downloads. The database side is dual, with `better-sqlite3` for local state and `pg` for Postgres, which suggests local-first operation with an optional hosted store.

What the list does not include is worth noticing too. There is no test framework dependency and the `test` script is the npm placeholder that echoes an error and exits.

## A Dockerfile that names its system dependencies

The Dockerfile is short and honest about what the bot needs from the operating system:

```bash
RUN apt-get update && apt-get install -y --no-install-recommends ffmpeg imagemagick webp && apt-get clean
WORKDIR /app
COPY package*.json ./
RUN npm install && npm cache clean --force
COPY . .
EXPOSE 3000
```

ffmpeg, imagemagick and webp are the three system tools that the JavaScript dependencies cannot replace, and installing them in the image is why the bot can transcode and process media without asking the host machine for anything. The layer order is correct as well: package files are copied and installed before the application code, so a source change does not invalidate the dependency layer.

`EXPOSE 3000` and `CMD ["npm", "run", "start"]` close the image, and the script that runs is `node index.js` even though `package.json` names `cypher.js` as the main entry. That inconsistency, with a dev script pointing at `nodemon cypher.js`, suggests the entry point was renamed at some point and the scripts were only partly updated.

The rest of the deployment files are the standard set for this kind of project: a `Procfile` for Heroku, `app.json` describing the app for the deploy button, and `heroku.yml` for the newer container-based deploy path. There is a `cx-platform.json` whose purpose is not documented anywhere in the repository.

## A release history that went backwards

The three most recent releases tell an unusual story. Version 2.0.3 on 2026-08-04 was a substantial fix release: AI services restored, actual DALL-E image generation, a fix for replies leaking between unrelated chats, updated API domains, HD media support through a new `hdmedia` setting, friendlier error messages, a repaired fancy text style generator, and an auto-updating launcher.

Version 2.0.4 on 2026-08-11 was smaller and Heroku focused, fixing the WhatsApp session, resetting the dashboard, fixing the ffmpeg package on Heroku, removing a false no saved session warning, and fixing disconnect loops during session migration.

Then version 1.8.4 on 2026-08-30, published after 2.0.4, whose entire release note is a revert of the whole codebase back to the 2025 version as voted by users. The version numbering going from 2.0.4 to 1.8.4 with a date stamp nineteen days later is not a mistake in the metadata, it is the project rolling back, and `package.json` in the repository still reads version 1.8.4, confirming the state of the tree.

So the practical reading is that CypherX's users did not want the 2.0 line, and the author agreed. If you are evaluating stability, that is the single most informative thing in the repository.

## What using this means for the linked phone number

None of this is legal advice or a policy judgement, but the mechanics matter more here than for a normal open source dependency. Because the bot logs in through an unofficial WhatsApp library, the number you attach to it is your real account, with your real contacts. There is no separate bot identity and no app registration.

That has several practical consequences. A number used to drive a bot is a number WhatsApp's abuse detection can act on, and accounts linked through unofficial libraries are exactly the pattern that gets flagged, whether or not the bot does anything aggressive. The repository's own README leads with pairing servers hosted by the author, which means the first-run flow involves trusting a third party server with your pairing flow.

The repository has no licence recorded, which for something people deploy against their personal accounts is a second reason to read carefully rather than assume terms. It is not archived, and the last push was on 2026-08-30, so the code is being actively maintained.

What is legitimate here is the engineering exercise. The dependency list is a genuinely instructive map of what it takes to build media handling, AI generation and scheduling into a chat bot, and the release notes are unusually candid about failures. Read it as a reference implementation with a caveat attached to running it.

## Conclusion

CypherX is worth reading as an example of how far a single WhatsApp bot library has been extended, because the dependency list is effectively a feature catalogue: media handling through ffmpeg and jimp, image generation through the Google GenAI SDK, PDF output, text to speech, a SQLite store and a Postgres client. The deployment story is equally conventional for that class of project, with a Procfile, a Heroku button in the README and a Dockerfile that installs ffmpeg, imagemagick and webp before starting npm. What is unusual is the release history, where a 2.0.4 followed by a 1.8.4 that reverted the whole codebase to a 2025 version by user vote tells you the project is run by its community rather than a roadmap. Set your expectations accordingly: expect breakage between releases. The account risk is the thing to weigh first, since the library links a real phone number rather than a bot account.

## FAQ

### What is CypherX?

CypherX is a Node.js WhatsApp bot that connects through an unofficial WhatsApp library rather than an official bot API. The repository documents two steps, forking the repository and deploying, and its dependency list covers media processing, DALL-E image generation, text to speech, PDF output and a SQLite or Postgres store.

### How do I run CypherX on my own server?

Build the included Dockerfile or deploy to Heroku using the deploy button in the README. The image installs ffmpeg, imagemagick and webp on top of a Node LTS base, exposes port 3000, and starts the bot with npm run start. You need Node 20 or newer but below 25 to run it outside the image.

### Which WhatsApp library does CypherX use?

It uses the Baileys library through an npm alias, resolving as @whiskeysockets/baileys but pinned to @tristancage/baileys at version 6.7.4. That fork pin is deliberate and means you get the fork's patches along with its compatibility constraints.

## Sources

- [Dark-Xploit/CypherX on GitHub](https://github.com/Dark-Xploit/CypherX)
- [Issues](https://github.com/Dark-Xploit/CypherX/issues)
- [Project website](https://www.cypherx.space)
- [README](https://github.com/Dark-Xploit/CypherX/blob/main/README.md)
- [Releases](https://github.com/Dark-Xploit/CypherX/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/dark-xploit-cypherx
