Core orchestration backbone for open-wa WhatsApp automation
Configured live patching downloads scripts and evaluates them in an authenticated WhatsApp Web page. No confirmed malicious payload is present in this snapshot.
Package source references dynamic code evaluation.
dist/transport/assets/base64.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/transport/assets/launch.jsView on unpkg · L4Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/transport/assets/wapi.jsView on unpkg · L19Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/transport/assets/init_patch.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/transport/assets/base64.js#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/transport/assets/hash.jsView on unpkgThis report applies to @open-wa/core@5.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic code evaluation.
dist/transport/assets/base64.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/transport/assets/base64.js#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/transport/assets/hash.jsView on unpkgPackage source references dynamic require/import behavior.
dist/transport/assets/launch.jsView on unpkg · L4Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/transport/assets/wapi.jsView on unpkg · L19Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/transport/assets/init_patch.jsView on unpkg · L1