itsmeeaizat-bailey@1.0.5
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17311
Ecosystem
npm
Summary
package.json declares the libsignal dependency as git+https://github.com/whiskeysockets/libsignal-node with no tag, no commit SHA, and no integrity constraint. On npm install, this resolves to whatever the default branch HEAD currently points at and executes any lifecycle scripts inside that fetched tree on the installer's machine — the delivered bytes and their behavior can change at any moment without a version bump to this package. Separately, the default socket factory in this Baileys fork wires an on-connection hook that, roughly 90 seconds after the installer's WhatsApp session opens, silently issues a FOLLOW MEX query for the hardcoded newsletter JID 120363400911374213@newsletter, which is owned by the package author. The behavior is not documented in the README and is only disableable via an undocumented autoFollowNewsletterOnConnect:false option, so the installer's authenticated WhatsApp identity is used to perform a social reach-padding action they did not opt into. No credential theft, exfiltration to an author endpoint, backdoor, or install-time destructive action is present in the shipped code.
Source: amazon-inspector (e87b4292727088efa5df8326a5f868b2c6bb3ae66ee15cecc18f2fa899296075)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.