megan-baileys@1.0.11
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-15919
Ecosystem
npm
Summary
The package's postinstall script walks up from its own install location into the consumer's node_modules directory, removes any existing @whiskeysockets/baileys directory there, and writes a replacement package.json whose main/exports point back into megan-baileys' own lib/index.mjs. After installation, any code in the installer's project — including transitive dependencies that legitimately declare @whiskeysockets/baileys — that calls require('@whiskeysockets/baileys') will silently load megan-baileys code instead of the genuine Baileys library published under the @whiskeysockets scope by a different maintainer. This is a dependency-tree hijack executed at install time via a lifecycle hook: the installer's declared dependency graph is mutated to substitute an unrelated author's code for a widely-used scoped package the installer never chose to replace.
Source: amazon-inspector (b6f79c4488100adec664b913cf1be5e70d50ee21eb475e084a6413fb3559ada0)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.