@xsat10/baileys-xsat @2.0.0
Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 10:16 PM UTC
OSV ID
MAL-2026-13390
Ecosystem
npm
Summary
Package is a fork of the Baileys WhatsApp Web library. Static keyword co-occurrence patterns matched on lib/Utils/generics.js (ping/GET references) and lib/Utils/messages-media.js (require('child_process') alongside POST/GET/hostname tokens), but these are consistent with Baileys' normal media upload/download paths and connectivity checks rather than a traced exfiltration flow. The concern is fork provenance: Baileys forks have previously been used to wire covert side effects (e.g. auto-follow of author-controlled newsletters, install counters) into the main exported API using the consumer's authenticated WhatsApp session. No specific installer-side data read and non-first-party destination pair has been identified in the code paths matched.
Source: amazon-inspector (37ba86faab85b50d9ae903ee59c78a8b52e46797b4c003448cd9851cd774939b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.