baoyu-post-to-wechat

Fail

Audited by Socket on May 25, 2026

1 alert found:

Malware
MalwareHIGH
scripts/wechat-article.ts

This module primarily performs WeChat posting automation, but it contains a high-risk supply-chain/security abuse behavior: it captures the WeChat login QR code from the browser and sends it to Telegram using bot credentials from environment variables. That is direct exfiltration of authentication-enabling material. Additionally, it heavily relies on CDP Runtime.evaluate with dynamically constructed expressions and executes local helper binaries via spawnSync, increasing overall risk. No direct system compromise primitives (e.g., reverse shell, file erasure) are evident in this fragment, but the QR-to-Telegram capability makes the package potentially malicious/abusive depending on its usage context.

Confidence: 60%Severity: 90%
Audit Metadata
Analyzed At
May 25, 2026, 05:39 AM
Package URL
pkg:socket/skills-sh/guanyang%2Fantigravity-skills%2Fbaoyu-post-to-wechat%2F@49b80594f8cc7a707770ccce635ac8bbe91aa5e8
Security Audit — socket — baoyu-post-to-wechat