
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@nam088/zca-js
Advanced tools
[!NOTE] This is an unofficial Zalo API for personal account. It work by simulating the browser to interact with Zalo Web.
[!WARNING] Using this API could get your account locked or banned. We are not responsible for any issues that may happen. Use it at your own risk.
bun add zca-js # or npm install zca-js
Since official version 2.0.0, zca-js has removed sharp dependency for image metadata extraction. It now requires users to provide their own imageMetadataGetter function when initializing the Zalo class if they want to send images/gifs by file path.
Example of custom imageMetadataGetter using sharp:
bun add sharp # or npm install sharp
import { Zalo } from "zca-js";
import sharp from "sharp";
import fs from "fs";
async function imageMetadataGetter(filePath) {
const data = await fs.promises.readFile(filePath);
const metadata = await sharp(data).metadata();
return {
height: metadata.height,
width: metadata.width,
size: metadata.size || data.length,
};
}
const zalo = new Zalo({
imageMetadataGetter,
});
See API Documentation for more details.
import { Zalo } from "zca-js";
const zalo = new Zalo();
const api = await zalo.loginQR();
import { Zalo, ThreadType } from "zca-js";
const zalo = new Zalo();
const api = await zalo.loginQR();
api.listener.on("message", (message) => {
const isPlainText = typeof message.data.content === "string";
switch (message.type) {
case ThreadType.User: {
if (isPlainText) {
// received plain text direct message
}
break;
}
case ThreadType.Group: {
if (isPlainText) {
// received plain text group message
}
break;
}
}
});
api.listener.start();
[!IMPORTANT] Only one web listener can run per account at a time. If you open Zalo in the browser while the listener is active, the listener will be automatically stopped.
import { Zalo, ThreadType } from "zca-js";
const zalo = new Zalo();
const api = await zalo.loginQR();
// Echo bot
api.listener.on("message", (message) => {
const isPlainText = typeof message.data.content === "string";
if (message.isSelf || !isPlainText) return;
switch (message.type) {
case ThreadType.User: {
api.sendMessage(
{
msg: "echo: " + message.data.content,
quote: message.data, // the message to reply to (optional)
},
message.threadId,
message.type, // ThreadType.User
);
break;
}
case ThreadType.Group: {
api.sendMessage(
{
msg: "echo: " + message.data.content,
quote: message.data, // the message to reply to (optional)
},
message.threadId,
message.type, // ThreadType.Group
);
break;
}
}
});
api.listener.start();
api.getStickers("hello").then(async (stickerIds) => {
// Get the first sticker
const stickerObject = await api.getStickersDetail(stickerIds[0]);
api.sendMessageSticker(
stickerObject,
message.threadId,
message.type, // ThreadType.User or ThreadType.Group
);
});
See examples folder for more details.
| Repository | Description |
|---|---|
| ZaloDataExtractor | A browser Extension to extract IMEI, cookies, and user agent from Zalo Web. |
| MultiZlogin | A multi-account Zalo management system that lets you log in to and manage multiple accounts simultaneously, with proxy and webhook integration. |
| n8n-nodes-zalo-tools | N8N node for personal Zalo account. |
| Zalo-F12 | A collection of JavaScript code snippets to paste into DevTools to change how Zalo Web/PC works. |
| Zalo-F12-Tools | Toggle hidden modes for Zalo Web. |
We welcome contributions from the community! Please see our Contributing Guidelines for details on how to:
For more information, please read our Code of Conduct and Security Policy before participating.
This project is licensed under the MIT License - see the LICENSE file for details.
FAQs
Unofficial Zalo API for JavaScript
We found that @nam088/zca-js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.