AURA — WhatsApp bot (npm/yarn package build)
Starting and pairing the bot persists WhatsApp authentication credentials and Signal keys to the package author's default remote shared MongoDB. Stored sessions are automatically restored on later launches.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
src/commands/tools.jsView on unpkg · L509Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/tools.jsView on unpkgSource appears to send environment or credential material to an external endpoint.
start.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
start.jsView on unpkg · L1Package ships high-entropy non-source blobs.
src/media/startup_voice.oggView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/extra_media.jsView on unpkgGoogle API key in src/commands/extra_media.js
src/commands/extra_media.jsView on unpkg · L33Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/myfunc2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/sticker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/unity_dl.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
start.jsView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11Source appears to send environment or credential material to an external endpoint.
start.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Package ships high-entropy non-source blobs.
src/media/startup_voice.oggView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/extra_media.jsView on unpkgGoogle API key in src/commands/extra_media.js
src/commands/extra_media.jsView on unpkg · L33Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/myfunc2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/sticker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/unity_dl.jsView on unpkgPackage contains a high-severity secret pattern.
src/commands/tools.jsView on unpkg · L509Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/tools.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
start.jsView on unpkg · L1