ron-tech whatsapp baileys modification
A runtime video-thumbnail path is concatenated into a shell command. This is a command-injection risk when an application passes an attacker-controlled local media path.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkgVideo-thumbnail helper interpolates file paths into an ffmpeg shell command executed via exec.
lib/Utils/messages-media.jsView on unpkg · L85This report applies to @ostyado/baileys@2.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L37Package contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgVideo-thumbnail helper interpolates file paths into an ffmpeg shell command executed via exec.
lib/Utils/messages-media.jsView on unpkg · L85Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkg