Logo
npm

@akapaki/baileys@1.0.2

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 11:11 PM UTC

Malicious

OSV ID

MAL-2026-17285

Ecosystem

npm

Summary

@akapaki/baileys@1.0.1 is an unofficial republish of the Baileys WhatsApp library under a new scope (author paki, empty README, repository pernapasquale647-dotcom/paki-baileys). Its package.json declares the libsignal dependency as github:pernapasquale647-dotcom/paki-libsignal — a personal GitHub source with no commit SHA, tag, or integrity pin. npm install will fetch whatever the repo's default branch currently contains and run any lifecycle scripts inside it on the installer's machine, giving the repository owner unilateral, unaudited control over code executed at install time. The shipped lib/ has not been diffed against upstream Baileys, so behavioral drift from the legitimate library cannot be excluded.

Source: amazon-inspector (c14fdf44df68d2544cc235039ef40a99c7df7bcbfc968e8d5809762031f0dd16)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.