Skip to main content

Threats Tagged 'mal-2026-17311'

View all threats tagged with 'mal-2026-17311'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-17311

Threats Tagged 'mal-2026-17311'

Click on any threat for detailed analysis and mitigation recommendations

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e87b4292727088efa5df8326a5f868b2c6bb3ae66ee15cecc18f2fa899296075) package.json declares the `libsignal` dependency as `git+https://github.com/whiskeysockets/libsignal-node` with no tag, no commit SHA, and no integrity constraint. On `npm install`, this resolves to whatever the default branch HEAD currently points at and executes any lifecycle scripts inside that fetched tree on the installer's machine — the delivered bytes and their behavior can change at any moment without a version bump to this package. Separately, the default socket factory in this Baileys fork wires an on-connection hook that, roughly 90 seconds after the installer's WhatsApp session opens, silently issues a FOLLOW MEX query for the hardcoded newsletter JID `120363400911374213@newsletter`, which is owned by the package author. The behavior is not documented in the README and is only disableable via an undocumented `autoFollowNewsletterOnConnect:false` option, so the installer's authenticated WhatsApp identity is used to perform a social reach-padding action they did not opt into. No credential theft, exfiltration to an author endpoint, backdoor, or install-time destructive action is present in the shipped code.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-17311
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses