VDB

GCVE-110-OSM-2026-12720

GCVE-110-OSM-2026-12720
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 29, 2026
@akapaki/baileys@1.0.1 is an unofficial republish of the Baileys WhatsApp library under a new scope (author `paki`, empty README, repository `pernapasquale647-dotcom/paki-baileys`). Its package.json declares the `libsignal` dependency as `github:pernapasquale647-dotcom/paki-libsignal` — a personal GitHub source with no commit SHA, tag, or integrity pin. `npm install` will fetch whatever the repo's default branch currently contains and run any lifecycle scripts inside it on the installer's machine, giving the repository owner unilateral, unaudited control over code executed at install time. The shipped lib/ has not been diffed against upstream Baileys, so behavioral drift from the legitimate library cannot be excluded. ENTRY engine-requirements.js (install-hook: node ./engine-requirements.js) - Install Hook Executes Local JS File in package.json PERSISTENCE - Startup Persistence in lib/Socket/chats.js: ".profile" - Startup Persistence in lib/Store/make-in-memory-store.js: ".profile" DESTINATION - 10 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Corporate Environment Targeting in WAProto/index.d.ts: "tModel. */ isLatest" - Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/messages.js: "Buffer.from(stickerMsg.fileSha256).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString('base64')" OBFUSCATION - Dynamic Base64 Decoding in lib/Signal/Group/group_cipher.js: "Buffer.from(iv, 'base64')" - Dynamic Base64 Decoding in lib/Signal/Group/sender-key-state.js: "Buffer.from(chainKey, 'base64')" - Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, 'base64')" - Dynamic Base64 Decoding in lib/Utils/generics.js: "Buffer.from(val, 'base64')" - Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, 'base64')" - String Array Obfuscation in lib/Utils/message-composer.js: "[ 'import', 'export', 'from', 'default', 'as', 'const', 'let', 'var', 'function'..." - String Array Obfuscation in lib/WABinary/constants.d.ts: "["1724", "profile_picture", "1071", "1314", "1605", "407", "990", "1710", "746",..." - String Array Obfuscation in lib/WABinary/constants.js: "[ '1724', 'profile_picture', '1071', '1314', '1605', '407', '990', '1710', '746'..." (+5 more) ADDITIONAL FINDINGS - Dynamic Code Execution in lib/Utils/message-composer.js: "exec(line)" - Shell Command Execution in lib/Utils/messages-media.js: "require("child_process")" - Publisher Has Other Malicious Packages PAYLOAD FILES lib/Utils/chat-utils.js (+ WAProto/index.d.ts, lib/Utils/messages-media.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@akapaki/baileysall (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›