VDB
GCVE-110-OSM-2026-12213
GCVE-110-OSM-2026-12213
Advisory PublishedCVSS 8.8/10
Versions 1.0.1 through 1.1.4 of jexkcode automatically follow a hard-coded WhatsApp newsletter whenever a WhatsApp connection opens. The package waits three seconds and calls newsletterFollow without obtaining user consent or exposing a configuration option. The README advertises newsletter support but does not disclose this automatic account modification. Versions through 1.1.1 used a malformed newsletter JID; version 1.1.2 corrected it. Subsequent commits removed both failure and success logs, so version 1.1.4 performs the automatic follow without visible output. This behavior is unrelated to the package's stated functionality and modifies the user's WhatsApp account without authorization.
ENTRY
engine-requirements.js (install-hook: node ./engine-requirements.js)
- Install Hook Executes Local JS File in package.json
PERSISTENCE
- Startup Persistence in lib/Socket/chats.js: ".profile"
- Startup Persistence in lib/Socket/messages-send.js: ".profile"
- Startup Persistence in lib/Store/make-in-memory-store.js: ".profile"
DESTINATION
- 1 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/generics.js: "Buffer.from(value?.data || value).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString('base64')"
- Network Request in lib/Utils/generics.js: "fetch('https:"
- Network Request in lib/Utils/messages-media.js: "request({ hostname: parsedUrl.hostname, port: parsedUrl.port || (parsedUrl.proto..."
OBFUSCATION
- Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, 'base64')"
- Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, 'base64')"
- String Array Obfuscation in lib/WABinary/constants.js: "[ '1724', 'profile_picture', '1071', '1314', '1605', '407', '990', '1710', '746'..."
- Strings Extracted from Deobfuscated Code in lib/Utils/chat-utils.js
- Strings Extracted from Deobfuscated Code in lib/Utils/validate-connection.js
ADDITIONAL FINDINGS
- Dynamic Code Execution in lib/Utils/rich-message-utils.js: "exec(code)"
- Very New NPM Publisher Account
- Rapid Version Publishing
PAYLOAD FILES
lib/Utils/generics.js (+ lib/Utils/messages-media.js, lib/Utils/chat-utils.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | jexkcode | all (affected) | — |
Aliases
Browse GCVE Records
395 records in the GCVE database · Updated September 17, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.