A WhatsApp Web (multi-device) library — a Baileys-based fork with a friendlier WAClient API, a native-flow Button builder, an interactive/rich message builder, call handling, working pairing codes, and complete docs.
OpenSSF/OSV advisory MAL-2026-17441 confirms this npm version as malicious. This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the "PhantomSub" family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer's own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
lib/WABinary/constants.jsView on unpkg · L600Google API key in lib/WABinary/constants.js
lib/WABinary/constants.jsView on unpkg · L600Package source references weak cryptographic algorithms.
lib/Utils/validate-connection.jsView on unpkg · L114Package ships non-JavaScript build or shell helper files.
WAProto/GenerateStatics.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
WAProto/index.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkgGoogle API key in lib/WABinary/constants.d.ts
lib/WABinary/constants.d.tsView on unpkg · L20This report applies to @fazzcodestudio/wa-web@0.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L52Package ships non-JavaScript build or shell helper files.
WAProto/GenerateStatics.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
WAProto/index.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkgPackage contains a high-severity secret pattern.
lib/WABinary/constants.jsView on unpkg · L600Google API key in lib/WABinary/constants.js
lib/WABinary/constants.jsView on unpkg · L600Package source references weak cryptographic algorithms.
lib/Utils/validate-connection.jsView on unpkg · L114Google API key in lib/WABinary/constants.d.ts
lib/WABinary/constants.d.tsView on unpkg · L20