{"id":"MAL-2026-17285","summary":"Malicious code in @akapaki/baileys (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c14fdf44df68d2544cc235039ef40a99c7df7bcbfc968e8d5809762031f0dd16)\n@akapaki/baileys@1.0.1 is an unofficial republish of the Baileys WhatsApp library under a new scope (author `paki`, empty README, repository `pernapasquale647-dotcom/paki-baileys`). Its package.json declares the `libsignal` dependency as `github:pernapasquale647-dotcom/paki-libsignal` — a personal GitHub source with no commit SHA, tag, or integrity pin. `npm install` will fetch whatever the repo's default branch currently contains and run any lifecycle scripts inside it on the installer's machine, giving the repository owner unilateral, unaudited control over code executed at install time. The shipped lib/ has not been diffed against upstream Baileys, so behavioral drift from the legitimate library cannot be excluded.\n","modified":"2026-09-29T21:30:08.066524299Z","published":"2026-09-29T21:11:58Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020672","import_time":"2026-09-29T21:18:13.395793258Z","modified_time":"2026-09-29T21:12:10Z","sha256":"0b075a3687b7dca26037d732cb682f79c4b9f3ff761fc6268a71982a311f46a5"},{"sha256":"28c9d6f6bb4eacd40be68ec8e1d2e33e70be84e1af18f9259647b8a77a8bf5f5","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-020671","import_time":"2026-09-29T21:18:13.315959167Z","modified_time":"2026-09-29T21:11:58Z"},{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020673","import_time":"2026-09-29T21:18:13.505094191Z","modified_time":"2026-09-29T21:12:20Z","sha256":"c14fdf44df68d2544cc235039ef40a99c7df7bcbfc968e8d5809762031f0dd16"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@akapaki/baileys/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@akapaki/baileys/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@akapaki/baileys/v/1.0.1"}],"affected":[{"package":{"name":"@akapaki/baileys","ecosystem":"npm","purl":"pkg:npm/%40akapaki/baileys"},"versions":["1.0.0","1.0.2","1.0.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"61ed9bc45552e09554caf7f6273889e047fadb29d76b9b97b06c8ca69dfbabdf","tlsh":"4b51fe21c95cdf3309c622d9697a000250b949679d94fc1c37994b6c8f4f16f33bae2e","path":"package.json"}],"package_integrity":[{"filename":"baileys-1.0.0.tgz","hashes":{"sha512_sri":"sha512-8MRaDBHbvKo5kvh9HyFQNgUolwev8zgBZDhw4sUMH79lQzmr/leJRRtAfDp523JgsZvbjZbwO0ynwnIUGAh87w==","sha1":"e77218ed71233fa593a6cc7a7e9f81df37f8fea8"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@akapaki/baileys/MAL-2026-17285.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}