OSV ID
MAL-2026-17405
Ecosystem
npm
Summary
lib/Socket/messages-send.js at lines 425 and 436 reconstructs the URL https://fiora.nixel.my.id/ from a String.fromCharCode decimal-ASCII array rather than a plain string literal. The host is assembled inside the package's WhatsApp socket message-send code path, so on every message-send flow the runtime resolves to an off-host destination whose identity is hidden from source-level inspection. Obfuscated destination reconstruction in a messaging library's send path is the fingerprint of a Baileys-family fork that intercepts or mirrors session/message data through an author-controlled endpoint; the destination fiora.nixel.my.id is unrelated to the WhatsApp protocol and is not documented as a caller-configurable endpoint.
Source: amazon-inspector (926dc7dcc164af51175755e81a7a6eabb878244ecc173974ab577a1569ce1ff4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.