whatsapp api multidevice by ChatUnity
OpenSSF/OSV advisory MAL-2026-17287 confirms this npm version as malicious. package.json declares the runtime dependency `libsignal` with the value `github:chatunitycenter/libsignal-node`, an off-registry git source with no commit SHA or tag pin. On `npm install`, npm fetches whatever the default branch of that repository currently contains and executes any lifecycle scripts inside it, and the module is then required transitively via lib/Signal/libsignal.js from the package's main entry...
This report applies to @chatunity/baileys@3.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.