Logo
npm

@itsmee_aizat.id/baileys2@2.0.2

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 7:51 PM UTC

Malicious

OSV ID

MAL-2026-17670

Ecosystem

npm

Summary

package.json declares "libsignal": "github:tenka-san/libsignal-node" as a runtime dependency. The source is a GitHub user account unrelated to the package publisher (itsmeeaizat1) and unrelated to the upstream Baileys project (WhiskeySockets), with no commit SHA, tag, or integrity check. npm install resolves the current HEAD of that repository and executes any lifecycle scripts it ships, so whoever controls tenka-san/libsignal-node controls code installed on the installer's machine. The shipped lib/Signal/libsignal.js requires this dependency by name, so the pulled code is loaded at runtime as well. The separate fetchLatestBaileysVersion / fetchLatestWaWebVersion GET requests to raw.githubusercontent.com/WhiskeySockets/Baileys and web.whatsapp.com/sw.js are read-only version probes with no installer data in the request body.

Source: amazon-inspector (c95f98902ced2f03261621ba4cb5386a892bf31ac4510b916708d3d3eb21aa50)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.