@badzz88/baileys@8.6.0
Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC
OSV ID
MAL-2026-17341
Ecosystem
npm
Summary
package.json declares a required runtime dependency whatsapp-rust-bridge-baron resolved to github:7ucg/whatsapp-rust-bridge with no commit SHA, tag, or integrity hash. On npm install, npm fetches the current default-branch HEAD of that repository and installs it into node_modules. The GitHub account 7ucg is not the publisher of this npm package (published under Badzz88), so an unrelated third party controls the code that lands on the installer's machine. The bridge module is required throughout the crypto, decode, and Noise-handler paths, so its code executes as soon as a consumer imports the package. Because the source is a mutable branch owned by a non-publisher account, the fetched bytes can change silently between installs, and there is no verification that today's HEAD matches any previously reviewed content. This is the classic unpinned-mutable-source install-time code-execution channel. Additional network/child_process/os primitives referenced in src/Utils/generics.js and src/Utils/messages-media.js are consistent with the upstream Baileys library shape (media download, ping-based connectivity checks) and are not by themselves evidence of exfiltration in this fork.
Source: amazon-inspector (8c4fc02c3ef351d891d52e60719cbd702d2f6a1db2d00847ac02ae7928de67b9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.