Facebook Chat API by EryXenX | Stable • Auto Re-login • Full E2EE Support — send messages, media, reactions & more in encrypted chats, hassle-free
A runtime login without an existing AppState or cookie sends the caller-provided Facebook email and password to a default third-party host. This is credential exfiltration, not needed for importing the package.
Package contains a high-severity secret pattern.
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Google API key in src/api/socket/e2ee/vendor/fme/dist/index.cjs
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/native/nativeMediaBridge.jsView on unpkg · L45Source file is highly similar to a previously finalized malicious package; route for source-aware review.
module/loginHelper.jsView on unpkgPackage source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgPackage ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/messaging/uploadAttachment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/users/getUserInfo.jsView on unpkgPackage source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgPackage ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/messaging/uploadAttachment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/users/getUserInfo.jsView on unpkgPackage contains a high-severity secret pattern.
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Google API key in src/api/socket/e2ee/vendor/fme/dist/index.cjs
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/native/nativeMediaBridge.jsView on unpkg · L45Source file is highly similar to a previously finalized malicious package; route for source-aware review.
module/loginHelper.jsView on unpkg