Logo
npm

saturn-baileys@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 1:33 PM UTC

Malicious

OSV ID

MAL-2026-17404

Ecosystem

npm

Summary

saturn-baileys is a fork of the Baileys WhatsApp library. In lib/Socket/messages-send.js at lines 425 and 436, a network destination is reconstructed at runtime from a String.fromCharCode(...) decimal array rather than appearing as a plain string literal. The decoded value is the URL https://fiora.nixel.my.id/. The obfuscation is placed inside the message-send code path of a messaging library that handles user credentials, session data, and message content, and the destination is not a documented WhatsApp/Baileys endpoint. Reconstructing a hardcoded non-first-party host via char-code decoding inside a send routine is the exfiltration/silent-relay shape for messaging-library trojans and is inconsistent with any legitimate use in this location.

Source: amazon-inspector (098af0c774d7e3d1a8b2da57e35d5e2686e2149ad6f01fa13803cd1a54325058)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.