Logo
npm

@kelvdra/baileys@1.0.6-rc.4

Vulnerability report · Last retrieved from osv.dev October 1, 2026 at 7:20 PM UTC

Malicious

OSV ID

MAL-2026-17362

Ecosystem

npm

Summary

package.json in @kelvdra/baileys@1.0.6-rc.4 declares the dependency libsignal as github:Kelvdra/libsignal with no version, tag, or commit SHA. On npm install, npm resolves this specifier to the current tip of the referenced repository's default branch and installs whatever bytes it returns, running any lifecycle scripts contained within them, with no integrity check. The dependency source is not the npm registry and not a pinned commit, so the code that lands on the installer's machine can change at any moment without any change to this package. Control of that GitHub account or repository translates directly into install-time code execution on every installer of this package.

Source: amazon-inspector (839545967c959062f79d5b217758730bd2c6a69219949c2eea494e75e3cfc12a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.