Facebook Chat API by EryXenX | Stable • Auto Re-login • Full E2EE Support — send messages, media, reactions & more in encrypted chats, hassle-free
Static analysis flagged 19 finding(s) at 97.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package contains a high-severity secret pattern.
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Google API key in src/api/socket/e2ee/vendor/fme/dist/index.cjs
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/native/nativeMediaBridge.jsView on unpkg · L80Package source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Package ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/threads/getThreadInfo.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/api/messaging/uploadAttachment.jsView on unpkgThis report applies to @eryxenx/fca@1.1.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Package ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/threads/getThreadInfo.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/api/messaging/uploadAttachment.jsView on unpkgPackage contains a high-severity secret pattern.
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Google API key in src/api/socket/e2ee/vendor/fme/dist/index.cjs
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/native/nativeMediaBridge.jsView on unpkg · L80