Unofficial Facebook Chat API for Node.js - Interact with Facebook Messenger programmatically
Login and default session recovery post Facebook email, password, and 2FA to https://minhdong.site/api/v1/facebook/login_ios. The example config names a different host, so omitting apiServer still sends secrets to the compiled minhdong.site receiver.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L36Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L36Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkgThis report applies to @cexy/wonfca@1.1.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L36Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L36Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkg