-= Per source details. Do not edit below this line.=-
This package is a fork of Baileys that declares libsignal in package.json as github:tenka-san/libsignal-node — a git dependency with no commit SHA, tag, or integrity check, resolving to whatever HEAD returns at install time and executing any lifecycle scripts inside it. The referenced GitHub account is unrelated to the upstream WhiskeySockets/libsignal-node maintainer, so its owner controls install-time code on every installer of this package. Separately, makeNewsletterSocket schedules a 120-second setTimeout after connection that fetches a channel-ID list from a hardcoded, mutable URL (raw.githubusercontent.com/MikuDevReal/V2.0/refs/heads/main/pepek.json) and issues QueryIds.FOLLOW on each entry using the installer's authenticated WhatsApp session, silently subscribing them to author-selected channels with no disclosure in the README. The remote list is author-mutable, so follow targets can change at any time.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020294",
"import_time": "2026-09-22T16:19:47.713128995Z",
"modified_time": "2026-09-22T16:05:11Z",
"sha256": "d03bf7166a5353a0b22409ebbb724ee53f24394c9ff340df668c970772796e28",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "6afbc001c9b1df6503e34354ca9929842ec1016e8abbec061ceea555ff14fec6",
"tlsh": "ff81dc74cd58cea30ac52ae899bd0142a47519139ec1f81cb35c47ac8f0e14f72b9b3e"
},
{
"path": "lib/Socket/newsletter.js",
"sha256": "358f54e30641cb4988e4dc1e07d53d00ad30eaa521973dc80a1af75fa2d7baf1",
"tlsh": "513240672476579616b37410967ff080b221b2437d1aa9663f8ca6120f4e1ede4e3bdc"
}
],
"package_integrity": [
{
"filename": "baileys-1.0.0.tgz",
"hashes": {
"sha1": "610c7eaaaa08e3e42b14c2817089a9d2a5bc1d89",
"sha512_sri": "sha512-HMUEdJ/jSBZ6ozNg+N8/bn1wRGOfbpxC+x0w8z+0gUyErOr+DTOkDWRAqrcu3ic8CvukhBDU+ce3qumKAhIAxw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@mikudeveloper/baileys/MAL-2026-16386.json"