OpenSSF/OSV advisory MAL-2026-16473 confirms this npm version as malicious. sea-baileys is a fork of the Baileys WhatsApp Web library. Its package.json remaps the `libsignal` import specifier to `npm:@otaxayun/libsignal-node@latest` — an unrelated maintainer's package pinned to the mutable `latest` dist-tag rather than a fixed version or integrity hash. lib/Signal/libsignal.js routes the installer's Signal Protocol identity private key, signed pre-key private key, session records and sender...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgThis report applies to sea-baileys@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkg