MAL-2026-17285

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@akapaki/baileys/MAL-2026-17285.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17285
Published
2026-09-29T21:11:58Z
Modified
2026-09-29T21:30:08Z
Summary
Malicious code in @akapaki/baileys (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (c14fdf44df68d2544cc235039ef40a99c7df7bcbfc968e8d5809762031f0dd16)

@akapaki/baileys@1.0.1 is an unofficial republish of the Baileys WhatsApp library under a new scope (author paki, empty README, repository pernapasquale647-dotcom/paki-baileys). Its package.json declares the libsignal dependency as github:pernapasquale647-dotcom/paki-libsignal — a personal GitHub source with no commit SHA, tag, or integrity pin. npm install will fetch whatever the repo's default branch currently contains and run any lifecycle scripts inside it on the installer's machine, giving the repository owner unilateral, unaudited control over code executed at install time. The shipped lib/ has not been diffed against upstream Baileys, so behavioral drift from the legitimate library cannot be excluded.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020672",
            "import_time":  "2026-09-29T21:18:13.395793258Z",
            "modified_time":  "2026-09-29T21:12:10Z",
            "sha256":  "0b075a3687b7dca26037d732cb682f79c4b9f3ff761fc6268a71982a311f46a5",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020671",
            "import_time":  "2026-09-29T21:18:13.315959167Z",
            "modified_time":  "2026-09-29T21:11:58Z",
            "sha256":  "28c9d6f6bb4eacd40be68ec8e1d2e33e70be84e1af18f9259647b8a77a8bf5f5",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-020673",
            "import_time":  "2026-09-29T21:18:13.505094191Z",
            "modified_time":  "2026-09-29T21:12:20Z",
            "sha256":  "c14fdf44df68d2544cc235039ef40a99c7df7bcbfc968e8d5809762031f0dd16",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @akapaki/baileys

Package

Name
@akapaki/baileys
View open source insights on deps.dev
Purl
pkg:npm/%40akapaki/baileys

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "61ed9bc45552e09554caf7f6273889e047fadb29d76b9b97b06c8ca69dfbabdf",
            "tlsh":  "4b51fe21c95cdf3309c622d9697a000250b949679d94fc1c37994b6c8f4f16f33bae2e"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "baileys-1.0.0.tgz",
            "hashes":  {
                "sha1":  "e77218ed71233fa593a6cc7a7e9f81df37f8fea8",
                "sha512_sri":  "sha512-8MRaDBHbvKo5kvh9HyFQNgUolwev8zgBZDhw4sUMH79lQzmr/leJRRtAfDp523JgsZvbjZbwO0ynwnIUGAh87w=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@akapaki/baileys/MAL-2026-17285.json"