Vulnerability MAL-2026-16220

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
16 hours ago
September 16, 2026 at 12:00 AM UTC
Malicious code in jexkcode (npm)
1.0.1 - 1.1.4
1.0.1 - 1.1.4

Summary

Malicious code in jexkcode (npm)

Details

Versions 1.0.1 through 1.1.4 of jexkcode automatically follow a hard-coded WhatsApp newsletter whenever a WhatsApp connection opens. The package waits three seconds and calls newsletterFollow without obtaining user consent or exposing a configuration option. The README advertises newsletter support but does not disclose this automatic account modification. Versions through 1.1.1 used a malformed newsletter JID; version 1.1.2 corrected it. Subsequent commits removed both failure and success logs, so version 1.1.4 performs the automatic follow without visible output. This behavior is unrelated to the package's stated functionality and modifies the user's WhatsApp account without authorization.

Impacted packages

Timeline

Published
16 hours ago
September 16, 2026 at 12:00 AM UTC
Last Modified
5 hours ago
September 16, 2026 at 10:15 AM UTC