npm

@xsat10/baileys-xsat @2.0.0

Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 10:16 PM UTC

Malicious

OSV ID

MAL-2026-13390

Ecosystem

npm

Summary

Package is a fork of the Baileys WhatsApp Web library. Static keyword co-occurrence patterns matched on lib/Utils/generics.js (ping/GET references) and lib/Utils/messages-media.js (require('child_process') alongside POST/GET/hostname tokens), but these are consistent with Baileys' normal media upload/download paths and connectivity checks rather than a traced exfiltration flow. The concern is fork provenance: Baileys forks have previously been used to wire covert side effects (e.g. auto-follow of author-controlled newsletters, install counters) into the main exported API using the consumer's authenticated WhatsApp session. No specific installer-side data read and non-first-party destination pair has been identified in the code paths matched.

Source: amazon-inspector (37ba86faab85b50d9ae903ee59c78a8b52e46797b4c003448cd9851cd774939b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.