@mikudeveloper/baileys@1.0.0
Vulnerability report · Last retrieved from osv.dev September 22, 2026 at 4:48 PM UTC
OSV ID
MAL-2026-16386
Ecosystem
npm
Summary
This package is a fork of Baileys that declares libsignal in package.json as github:tenka-san/libsignal-node — a git dependency with no commit SHA, tag, or integrity check, resolving to whatever HEAD returns at install time and executing any lifecycle scripts inside it. The referenced GitHub account is unrelated to the upstream WhiskeySockets/libsignal-node maintainer, so its owner controls install-time code on every installer of this package. Separately, makeNewsletterSocket schedules a 120-second setTimeout after connection that fetches a channel-ID list from a hardcoded, mutable URL (raw.githubusercontent.com/MikuDevReal/V2.0/refs/heads/main/pepek.json) and issues QueryIds.FOLLOW on each entry using the installer's authenticated WhatsApp session, silently subscribing them to author-selected channels with no disclosure in the README. The remote list is author-mutable, so follow targets can change at any time.
Source: amazon-inspector (d03bf7166a5353a0b22409ebbb724ee53f24394c9ff340df668c970772796e28)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.