@bottino/baileys@1.0.14
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC
OSV ID
MAL-2026-17351
Ecosystem
npm
Summary
This fork of Baileys overrides requestPairingCode so that when the caller does not supply an explicit pairKey, authState.creds.pairingCode is set to the fixed literal string BYPAKI64. That value is then used as the KDF input for the WhatsApp companion-device link-code encryption via derivePairingCodeKey(authState.creds.pairingCode, salt). Because the pairing code is a known constant baked into the package, anyone who knows the target phone number of the installer's WhatsApp account can complete the companion-device pair flow from a device they control and obtain persistent access to the installer's WhatsApp session (read/send messages, contacts, media) — a full account takeover backdoor against any application built on this library. Additionally, on socket connect the code auto-subscribes the installer's WhatsApp account to a hardcoded newsletter JID 120363418582531215@newsletter and persists a basedbysam flag so the covert subscribe runs once per credential store; this covert action uses the installer's WhatsApp identity without disclosure.
Source: amazon-inspector (571d52cf3274d95d4824667269921b2e0ad1478fe9f324a74fab0ba377bb9a26)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.