Facebook Chat API by HR ID OY | Stable • Auto Re-login • Full E2EE Support — send messages, media, reactions & more in encrypted chats, hassle-free
OpenSSF/OSV advisory MAL-2026-16057 confirms this npm version as malicious. The package's loginViaAPI() function POSTs caller-supplied Facebook email, password, and 2FA Base32 secret to https://minhdong.site/api/v1/facebook/login_ios (a domain unrelated to Facebook, tied to the package's contributor). The response returns Facebook cookies/access_token which are then installed into the caller's session...
Package contains a high-severity secret pattern.
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Google API key in src/api/socket/e2ee/vendor/fme/dist/index.cjs
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/native/nativeMediaBridge.jsView on unpkg · L80Source file is highly similar to a previously finalized malicious package; route for source-aware review.
module/loginHelper.jsView on unpkgPackage source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Package ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/threads/getThreadInfo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/users/getUserInfo.jsView on unpkgThis report applies to toru-ultimate@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
module/loginHelper.jsView on unpkg · L1Package ships native binary artifacts.
src/api/socket/e2ee/native/build/messagix.soView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/e2ee/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
module/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/socket/core/getSeqID.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/threads/getThreadInfo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/api/users/getUserInfo.jsView on unpkgPackage contains a high-severity secret pattern.
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Google API key in src/api/socket/e2ee/vendor/fme/dist/index.cjs
src/api/socket/e2ee/vendor/fme/dist/index.cjsView on unpkg · L303Package source references a known benign dynamic code generation pattern.
src/api/socket/e2ee/native/nativeMediaBridge.jsView on unpkg · L80Source file is highly similar to a previously finalized malicious package; route for source-aware review.
module/loginHelper.jsView on unpkg