@dreamguyxeon/libsignal-node@1.0.3
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-13931
Ecosystem
npm
Summary
Package is published as a Signal protocol implementation but its shipped code has no Signal functionality. index.js schedules install.js one second after require(). install.js locates the installer's @whiskeysockets/baileys module and overwrites lib/Socket/newsletter.js with an embedded replacement, drops a marker file at baileys/node_modules/.cache containing 'Iove' to make the tamper persistent and idempotent, and forces process.exit(0) 20 seconds later, abruptly terminating the host process. The replacement newsletter.js fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json (a personal GitHub repo, mutable main branch) and iterates the returned IDs to call newsletterWMexQuery(id, QueryIds.FOLLOW), causing the installer's authenticated WhatsApp session to follow attacker-chosen channels. Because the injected file is a full rewrite of the dependency's source and the remote list is mutable and unauthenticated, the author retains the ability to change the JSON at any time to drive arbitrary newsletter operations on every installer's WhatsApp account, and could substitute more damaging behavior into the rewritten newsletter.js path.
Source: amazon-inspector (4a3df23ac106ff1cebc25aade4a3e3cc3da77bc493c20b2e0b37e90807f51ea1)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.