Malicious code in @dknzo/soonex-ai (npm)
-= Per source details. Do not edit below this line.=-
The package advertises itself as 'Internal core lifecycle utilities for Baileys socket connection' but its sole exported function initSocketLifecycle(socket) performs only one action: it invokes socket.newsletterFollow('120363427659235345@newsletter') on the caller-supplied WhatsApp socket, causing the installer's WhatsApp account to silently follow a hardcoded newsletter owned by the package author. The action is undisclosed in the package's name, description, or README, and errors are swallowed so the caller cannot detect the side effect. This is a deceptive use of a generically-named utility to perform a non-consensual action on the installer's account using their authenticated session — the canonical silent-relay shape, where calling a function with an innocuous-sounding signature produces a benefit for the author at the caller's expense.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준