VYPR

npm · Malicious package advisory

Malware

@dknzo/soonex-ai

MAL-2026-4383

Malicious code in @dknzo/soonex-ai (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (637d9821dd6061c21dfa483bdefec73cd6ddeb8ba6e1d9bd9653784de514e9b5)
The package advertises itself as 'Internal core lifecycle utilities for Baileys socket connection' but its sole exported function `initSocketLifecycle(socket)` performs only one action: it invokes `socket.newsletterFollow('120363427659235345@newsletter')` on the caller-supplied WhatsApp socket, causing the installer's WhatsApp account to silently follow a hardcoded newsletter owned by the package author. The action is undisclosed in the package's name, description, or README, and errors are swallowed so the caller cannot detect the side effect. This is a deceptive use of a generically-named utility to perform a non-consensual action on the installer's account using their authenticated session — the canonical silent-relay shape, where calling a function with an innocuous-sounding signature produces a benefit for the author at the caller's expense.

Compromised versions (2)

  • 1.0.0
  • 1.0.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.