@akapaki/baileys@1.0.2
Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 11:11 PM UTC
OSV ID
MAL-2026-17285
Ecosystem
npm
Summary
@akapaki/baileys@1.0.1 is an unofficial republish of the Baileys WhatsApp library under a new scope (author paki, empty README, repository pernapasquale647-dotcom/paki-baileys). Its package.json declares the libsignal dependency as github:pernapasquale647-dotcom/paki-libsignal — a personal GitHub source with no commit SHA, tag, or integrity pin. npm install will fetch whatever the repo's default branch currently contains and run any lifecycle scripts inside it on the installer's machine, giving the repository owner unilateral, unaudited control over code executed at install time. The shipped lib/ has not been diffed against upstream Baileys, so behavioral drift from the legitimate library cannot be excluded.
Source: amazon-inspector (c14fdf44df68d2544cc235039ef40a99c7df7bcbfc968e8d5809762031f0dd16)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.