Facebook Chat API by EryXenX | Stable • Auto Re-login • Full E2EE Support — send messages, media, reactions & more in encrypted chats, hassle-free
On login recovery, the package submits configured Facebook credentials to a third-party default host. This is not needed for a local client API and exposes account secrets.
Package contains a high-severity secret pattern.
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Google API key in src/api/socket/e2ee/vendor/fme/dist/index.cjs
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/native/nativeMediaBridge.jsView on unpkg · L45Source file is highly similar to a previously finalized malicious package; route for source-aware review.
module/loginHelper.jsView on unpkgPackage source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgPackage ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/messaging/uploadAttachment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/threads/getThreadInfo.jsView on unpkgPackage source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgPackage ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/messaging/uploadAttachment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/threads/getThreadInfo.jsView on unpkgPackage contains a high-severity secret pattern.
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Google API key in src/api/socket/e2ee/vendor/fme/dist/index.cjs
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/native/nativeMediaBridge.jsView on unpkg · L45Source file is highly similar to a previously finalized malicious package; route for source-aware review.
module/loginHelper.jsView on unpkg