XcV Company
OpenSSF/OSV advisory MAL-2026-17452 confirms this npm version as malicious. This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the "PhantomSub" family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer's own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp `w:mex` FOLLOW query (query_id...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
lib/WABinary/constants.jsView on unpkg · L600Google API key in lib/WABinary/constants.js
lib/WABinary/constants.jsView on unpkg · L600Package source references weak cryptographic algorithms.
lib/Utils/validate-connection.jsView on unpkg · L107Package ships non-JavaScript build or shell helper files.
WAProto/GenerateStatics.shView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/Utils/business.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkgThis report applies to xcvrenzcompany@2.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L39Package ships non-JavaScript build or shell helper files.
WAProto/GenerateStatics.shView on unpkgPackage contains source files above the normal full-analysis size ceiling.
WAProto/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/Utils/business.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/Utils/messages-media.jsView on unpkgPackage contains a high-severity secret pattern.
lib/WABinary/constants.jsView on unpkg · L600Google API key in lib/WABinary/constants.js
lib/WABinary/constants.jsView on unpkg · L600Package source references weak cryptographic algorithms.
lib/Utils/validate-connection.jsView on unpkg · L107