MAL-2026-16220

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jexkcode/MAL-2026-16220.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16220
Published
2026-09-16T00:00:00Z
Modified
2026-09-16T10:15:09Z
Summary
Malicious code in jexkcode (npm)
Details

Versions 1.0.1 through 1.1.4 of jexkcode automatically follow a hard-coded WhatsApp newsletter whenever a WhatsApp connection opens. The package waits three seconds and calls newsletterFollow without obtaining user consent or exposing a configuration option. The README advertises newsletter support but does not disclose this automatic account modification. Versions through 1.1.1 used a malformed newsletter JID; version 1.1.2 corrected it. Subsequent commits removed both failure and success logs, so version 1.1.4 performs the automatic follow without visible output. This behavior is unrelated to the package's stated functionality and modifies the user's WhatsApp account without authorization.

References
Credits

Affected packages

npm / jexkcode

Package

Affected ranges

Affected versions

1.*
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jexkcode/MAL-2026-16220.json"