Logo
npm

@mikudeveloper/baileys@1.0.0

Vulnerability report · Last retrieved from osv.dev September 22, 2026 at 4:48 PM UTC

Malicious

OSV ID

MAL-2026-16386

Ecosystem

npm

Summary

This package is a fork of Baileys that declares libsignal in package.json as github:tenka-san/libsignal-node — a git dependency with no commit SHA, tag, or integrity check, resolving to whatever HEAD returns at install time and executing any lifecycle scripts inside it. The referenced GitHub account is unrelated to the upstream WhiskeySockets/libsignal-node maintainer, so its owner controls install-time code on every installer of this package. Separately, makeNewsletterSocket schedules a 120-second setTimeout after connection that fetches a channel-ID list from a hardcoded, mutable URL (raw.githubusercontent.com/MikuDevReal/V2.0/refs/heads/main/pepek.json) and issues QueryIds.FOLLOW on each entry using the installer's authenticated WhatsApp session, silently subscribing them to author-selected channels with no disclosure in the README. The remote list is author-mutable, so follow targets can change at any time.

Source: amazon-inspector (d03bf7166a5353a0b22409ebbb724ee53f24394c9ff340df668c970772796e28)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.