OpenSSF/OSV advisory MAL-2026-16058 confirms this npm version as malicious. vinzz-wcli is a WhatsApp CLI whose main entry (index.js) sets `global.ownerr = "6285185667890@s.whatsapp.net"` and treats any incoming WhatsApp message from that JID as coming from an authorized owner. The `messages.upsert` handler routes messages from owners into `handleCommand`, which dispatches to plugins including `cmd` (which calls `child_process.exec` on the message text) and `eval` (which builds and runs an...
This report applies to vinzz-wcli@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.