Logo
npm

shadowmd@8.6.87

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-17405

Ecosystem

npm

Summary

lib/Socket/messages-send.js at lines 425 and 436 reconstructs the URL https://fiora.nixel.my.id/ from a String.fromCharCode decimal-ASCII array rather than a plain string literal. The host is assembled inside the package's WhatsApp socket message-send code path, so on every message-send flow the runtime resolves to an off-host destination whose identity is hidden from source-level inspection. Obfuscated destination reconstruction in a messaging library's send path is the fingerprint of a Baileys-family fork that intercepts or mirrors session/message data through an author-controlled endpoint; the destination fiora.nixel.my.id is unrelated to the WhatsApp protocol and is not documented as a caller-configurable endpoint.

Source: amazon-inspector (926dc7dcc164af51175755e81a7a6eabb878244ecc173974ab577a1569ce1ff4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.