-= Per source details. Do not edit below this line.=-
package.json declares the libsignal dependency as git+https://github.com/whiskeysockets/libsignal-node with no tag, no commit SHA, and no integrity constraint. On npm install, this resolves to whatever the default branch HEAD currently points at and executes any lifecycle scripts inside that fetched tree on the installer's machine — the delivered bytes and their behavior can change at any moment without a version bump to this package. Separately, the default socket factory in this Baileys fork wires an on-connection hook that, roughly 90 seconds after the installer's WhatsApp session opens, silently issues a FOLLOW MEX query for the hardcoded newsletter JID 120363400911374213@newsletter, which is owned by the package author. The behavior is not documented in the README and is only disableable via an undocumented autoFollowNewsletterOnConnect:false option, so the installer's authenticated WhatsApp identity is used to perform a social reach-padding action they did not opt into. No credential theft, exfiltration to an author endpoint, backdoor, or install-time destructive action is present in the shipped code.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020789",
"import_time": "2026-09-30T02:52:56.39972635Z",
"modified_time": "2026-09-30T01:46:53Z",
"sha256": "aa89fc4b6ac9b670004406f8d95eee96891afc83758b023cf6fdeb23c70abcdc",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-020788",
"import_time": "2026-09-30T02:52:56.295456306Z",
"modified_time": "2026-09-30T01:46:43Z",
"sha256": "d33df45ab827c11b7a27184ffdfe922765eaafb919cd6908cdc715453cadbeac",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-020792",
"import_time": "2026-09-30T02:52:56.775390735Z",
"modified_time": "2026-09-30T01:47:20Z",
"sha256": "e87b4292727088efa5df8326a5f868b2c6bb3ae66ee15cecc18f2fa899296075",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "042cfd491fa93d75cbc274de488d0cea367a0a3f1b3862b7bb28e655a585b223",
"tlsh": "6441ba24cc289eb305c526e8acba4102e57069538d44fc2c73c9432c8f8d15f7bbabad"
}
],
"package_integrity": [
{
"filename": "itsmeeaizat-bailey-1.0.4.tgz",
"hashes": {
"sha1": "e66a37f396de0be47cd4fd0f3df4e2376a2b3035",
"sha512_sri": "sha512-/oa5I9aiTmqxMQDGsFvz23eCv6ol5siP7KdIA0k8eXqQFfk8mtiZXMqu/W2Gs0MWBMXtVZZ2woT5klENosG1WQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/itsmeeaizat-bailey/MAL-2026-17311.json"