AURA — WhatsApp bot (npm/yarn package build)
When the bot receives a reaction, it can send the reactor's number, reaction, and an excerpt of the reacted-to message to a hard-coded Telegram recipient. The package also performs conditional Termux system-package installation during preinstall.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
dist/src/commands/tools.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/tools.jsView on unpkgGoogle API key in dist/src/commands/tools.js
dist/src/commands/tools.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/start.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/start.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/start.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/extra_media.jsView on unpkgGoogle API key in dist/src/commands/extra_media.js
dist/src/commands/extra_media.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/sticker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_dl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_extra.jsView on unpkgThis report applies to @astralcore/aura-wb@1.0.32.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/start.jsView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/extra_media.jsView on unpkgGoogle API key in dist/src/commands/extra_media.js
dist/src/commands/extra_media.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/sticker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_dl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/unity_extra.jsView on unpkgPackage contains a high-severity secret pattern.
dist/src/commands/tools.jsView on unpkg · L1Google API key in dist/src/commands/tools.js
dist/src/commands/tools.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/tools.jsView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/start.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/start.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/start.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/start.jsView on unpkg · L1