MAL-2026-14260Malicious code in ranux-pro (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | ranux-pro | 2.0.0 |
{"modified":"2026-08-19T04:59:38Z","published":"2026-08-19T04:59:38Z","schema_version":"1.7.4","id":"MAL-2026-14260","summary":"Malicious code in ranux-pro (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (535aa6b18b45b3ade8ae934157747b2a3281c298e38c7a8aa308236ba3c941a2)\npackage.json advertises the package as a 'High-performance async network socket & runtime protocol engine', but the tarball ships a multi-tenant WhatsApp bot: lib/baileysMod.js, plugins/pair.js (WA pairing), plugins/antidelete.js, plugins/adult.js, tenantManager.js (~134KB), database.js backed by mongodb. The @whiskeysockets/baileys dependency is redirected to `github:rcedubot/X` — a personal GitHub account's repo named 'X', pinned to no commit SHA, so every install pulls whatever code that account currently hosts into node_modules and executes it when the package is loaded. Every JS file (command.js, config.js, database.js, tenantManager.js, lib/*, plugins/*) is emitted by obfuscator.io with rotated string arrays, control-flow flattening, and self-defending IIFEs, so all network destinations and command handlers are hidden inside encoded string arrays and no URL literals are recoverable by static inspection. The combination of a deceptive registry description, whole-package obfuscation, and a mutable personal-fork override of the WhatsApp protocol layer means installers receive attacker-mutable code at install/load time and, once paired, hand persistent control of the WhatsApp session to whoever owns the concealed endpoints in tenantManager.js.\n","affected":[{"package":{"ecosystem":"npm","name":"ranux-pro"},"versions":["2.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"69acfa59626d5d0ab4c4baef4fe6afafa64c349dd928bd118e86924e1e55768b","tlsh":"acf0c912cd60887324c86ec59ca916437ba048070a05fc1c33e6a72cabdc0ef31b9bac"},{"path":"index.js","sha256":"dad7bda183ba57d8994a707fe8ad646a34db1172e9ceff53906132a3b58be711","tlsh":"1564732253c17c41124b9fb7b71bb3e9fa195bbc704848abe214bd64f7ba502d6d0932"},{"path":"tenantManager.js","sha256":"2ae368a37f83046ee23c076cedcc97bcb1c81540e0a3cab24e99637ac6a7fbe1","tlsh":"cbd3a471b3c4bc81224b4f77771ff6e5e92969a975880c8be104bc54f7a9a06ebd0930"}],"package_integrity":[{"filename":"ranux-pro-2.0.0.tgz","hashes":{"sha1":"d8d506884ae3762ce72cbe8174090f651f55e339","sha512_sri":"sha512-zVaB9tx/VJR3S0PrR+efkP2QRbqXhHZYMlfXd3CE97fIsx5hjG0pF+ouje0M1wznNNRGJyZRLrNnVy81vcL2NQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ranux-pro/v/2.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018369","import_time":"2026-08-19T05:13:49.585194482Z","modified_time":"2026-08-19T04:59:38Z","sha256":"535aa6b18b45b3ade8ae934157747b2a3281c298e38c7a8aa308236ba3c941a2","source":"amazon-inspector","versions":["2.0.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0