VDB
Sign up

MAL-2026-16220

Malicious code in jexkcode (npm)

Details

Versions 1.0.1 through 1.1.4 of jexkcode automatically follow a hard-coded WhatsApp newsletter whenever a WhatsApp connection opens. The package waits three seconds and calls newsletterFollow without obtaining user consent or exposing a configuration option. The README advertises newsletter support but does not disclose this automatic account modification. Versions through 1.1.1 used a malformed newsletter JID; version 1.1.2 corrected it. Subsequent commits removed both failure and success logs, so version 1.1.4 performs the automatic follow without visible output. This behavior is unrelated to the package's stated functionality and modifies the user's WhatsApp account without authorization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jexkcode

No fixed version published yet for jexkcode (npm). Pin to a known-safe version or switch to an alternative.

References