FCA Raihan - Facebook Chat API compatibility build with stable MQTT theme and nickname methods
The login workflow can expose Facebook credentials and a two-factor secret to an external API server. This establishes a concrete credential exposure risk, but no confirmed malicious attack.
Package contains a high-severity secret pattern.
src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjsView on unpkg · L2964Google API key in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs
src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjsView on unpkg · L2964Package source references weak cryptographic algorithms.
src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjsView on unpkg · L130Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/e2ee/nativeBridge.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/e2ee/nativeBridge.jsView on unpkg · L37This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
module/loginHelper.jsView on unpkgPackage source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgPackage ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgPackage ships high-entropy non-source blobs.
src/vendor/fca-unofficial/test/data/something.movView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
src/vendor/fca-unofficial/test/data/something.movView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/vendor/fca-unofficial/utils.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/nativeBridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/e2ee/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/threads/getThreadInfo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/users/getUserInfo.jsView on unpkgGoogle API key in src/api/socket/e2ee/vendor/fb-e2ee.cjs
src/api/socket/e2ee/vendor/fb-e2ee.cjsView on unpkg · L2964This report applies to fca-raihan@37.2.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references weak cryptographic algorithms.
src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjsView on unpkg · L130Package source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgPackage ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgPackage ships high-entropy non-source blobs.
src/vendor/fca-unofficial/test/data/something.movView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
src/vendor/fca-unofficial/test/data/something.movView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/vendor/fca-unofficial/utils.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/nativeBridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/e2ee/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/threads/getThreadInfo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/users/getUserInfo.jsView on unpkgPackage contains a high-severity secret pattern.
src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjsView on unpkg · L2964Google API key in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs
src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjsView on unpkg · L2964Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/e2ee/nativeBridge.jsView on unpkg · L37Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/e2ee/nativeBridge.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
module/loginHelper.jsView on unpkgGoogle API key in src/api/socket/e2ee/vendor/fb-e2ee.cjs
src/api/socket/e2ee/vendor/fb-e2ee.cjsView on unpkg · L2964