WhatsApp API Modification
A caller that passes an attacker-controlled video file path to the exported thumbnail helper can trigger shell command injection. No install-time attack behavior was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkgAn exported video-thumbnail path builds an ffmpeg shell command by interpolating the supplied file path and executes it with child_process.exec.
lib/Utils/messages-media.jsView on unpkg · L85This report applies to shadowmd@8.6.87.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33Package contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgAn exported video-thumbnail path builds an ffmpeg shell command by interpolating the supplied file path and executes it with child_process.exec.
lib/Utils/messages-media.jsView on unpkg · L85Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkg