@vinnxcode/xbailsync @1.0.1
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-11080
Ecosystem
npm
Summary
@vinnxcode/xbailsync 1.0.1 is a fork/republish of the Baileys WhatsApp Web library. A a static rule fired on lib/Utils/generics.js due to co-occurrence of the tokens 'ping' and 'GET' in a utility file, which is the shape of network/HTTP helper code common to this library family. No concrete installer-harm path is present: there is no traced code that reads installer secrets (~/.aws, ~/.ssh, ~/.npmrc, env scraping, browser stores), no hardcoded attacker C2 destination bound to an exfiltration primitive, no install-time or import-time fetch-and-execute, no lifecycle scripts performing outbound network calls, and no dropper or backdoor mechanism. The pattern matched is keyword adjacency, not a demonstrable exfiltration flow.
Source: amazon-inspector (aa85bc699ec69bbebf0799696e784cee3fcd9f78f5ccc9e2cb032e9a9cb3de68)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.