Malicious code in chromestaff-baileys (npm)
-= Per source details. Do not edit below this line.=-
chromestaff-baileys is a fork of the Baileys WhatsApp library that, on every successful WhatsApp connection, silently forces the connected user's WhatsApp account to follow a hardcoded author-controlled newsletter (120363418582531215@newsletter). In lib/Socket/socket.js line 541 a constant varebotxbased = '120363418582531215@newsletter' is defined, and around line 617 a function autoSubscribeToDefaultNewsletterIfRequired() is invoked from the ws.on('CB:success',...) handler, calling followNewsletterWMex(varebotxbased, timeoutMs). The action is undocumented, gated by a creds.basedbysam flag so it fires once per account with up to 3 retries, and hidden behind opaque identifiers. Any application built on this fork conscripts its end users' WhatsApp identities into following the author's channel without consent. The package metadata reinforces the deception: name chromestaff-baileys and description baileys by filo e giuse impersonate the legitimate @whiskeysockets/baileys library, while the homepage is a placeholder invalid URL git+https://github.com/precisione.git. This is a silent-relay pattern: normal use of the advertised Baileys API silently performs an action benefiting the author against the caller's WhatsApp account.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준