Core orchestration backbone for open-wa WhatsApp automation
No confirmed malicious package-install or host attack surface. The main risk is intentional remote JS patch/license execution inside the controlled WhatsApp Web page during client startup or license unlock.
Package source references dynamic code evaluation.
dist/transport/assets/base64.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/transport/assets/launch.jsView on unpkg · L4Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/transport/assets/wapi.jsView on unpkg · L19Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/transport/assets/init_patch.jsView on unpkg · L1This report applies to @open-wa/core@5.0.0-alpha.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic code evaluation.
dist/transport/assets/base64.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/transport/assets/launch.jsView on unpkg · L4Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/transport/assets/wapi.jsView on unpkg · L19Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/transport/assets/init_patch.jsView on unpkg · L1