CORTANA MD WhatsApp Bot — Self-Hosted Edition
OpenSSF/OSV advisory MAL-2026-17323 confirms this npm version as malicious. cortana-md-engine is a Baileys-based WhatsApp bot whose bundled entrypoints dist/hosted.cjs and dist/index.cjs hardcode five mongodb+srv://cortanauser:...@{cluster2.uvds2qk,cluster3.t2gtazm,cluster4.bwuctn9,cluster5.kdkad04,mass.gcijtck}.mongodb.net Atlas connection strings and, at bot startup, persist the Baileys authState/creds (Session/authState/sessions collections) into those clusters...
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/hosted.cjsView on unpkg · L1182Package source references dynamic require/import behavior.
dist/hosted.cjsView on unpkg · L6Package source references weak cryptographic algorithms.
dist/hosted.cjsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/index.cjsView on unpkg · L1This report applies to cortana-md-engine@1.4.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.cjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/hosted.cjsView on unpkg · L1182Package source references dynamic require/import behavior.
dist/hosted.cjsView on unpkg · L6Package source references weak cryptographic algorithms.
dist/hosted.cjsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/index.cjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.cjsView on unpkg · L1