WhatsApp Web API Library
OpenSSF/OSV advisory MAL-2026-17445 confirms this npm version as malicious. This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the "PhantomSub" family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer's own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
lib/WABinary/constants.jsView on unpkg · L603Google API key in lib/WABinary/constants.js
lib/WABinary/constants.jsView on unpkg · L603Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
lib/Utils/messages-media.jsView on unpkg · L369A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
WAProto/index.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages.jsView on unpkgThis report applies to ichigo-baileys@1.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L45A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
WAProto/index.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages.jsView on unpkgPackage contains a high-severity secret pattern.
lib/WABinary/constants.jsView on unpkg · L603Google API key in lib/WABinary/constants.js
lib/WABinary/constants.jsView on unpkg · L603Package source references a known benign dynamic code generation pattern.
lib/Utils/messages-media.jsView on unpkg · L369Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkg