AURA — WhatsApp bot (npm/yarn package build)
WhatsApp authentication state is uploaded to a shared database by default. This establishes credential exposure risk, but the inspected persistence flow does not establish deliberate theft.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
dist/src/commands/tools.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/tools.jsView on unpkgGoogle API key in dist/src/commands/tools.js
dist/src/commands/tools.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/start.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/start.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/start.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/extra_media.jsView on unpkgGoogle API key in dist/src/commands/extra_media.js
dist/src/commands/extra_media.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/myfunc2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/sticker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_dl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_extra.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_img_extra.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/media.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/parser.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/sessionManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/scripts/ensure-termux-deps.jsView on unpkgThis report applies to @astralcore/aura-wb@1.0.30.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/start.jsView on unpkgPackage source references dynamic require/import behavior.
dist/start.jsView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/extra_media.jsView on unpkgGoogle API key in dist/src/commands/extra_media.js
dist/src/commands/extra_media.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/myfunc2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/sticker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_dl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_extra.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_img_extra.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/media.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/parser.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/sessionManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/scripts/ensure-termux-deps.jsView on unpkgPackage contains a high-severity secret pattern.
dist/src/commands/tools.jsView on unpkg · L1Google API key in dist/src/commands/tools.js
dist/src/commands/tools.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/tools.jsView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/start.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/start.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/start.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/start.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/start.jsView on unpkg