npm

@openclaw-cn/libsignal @2.1.1

Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 3:29 AM UTC

Malicious

OSV ID

MAL-2026-3843

Ecosystem

npm

Summary

The package @openclaw-cn/libsignal was found to contain malicious code.

Source: amazon-inspector (85fb1bd455a85140d13ec5cb826c0f8c6164c87a6eeacd72f7fc525440b76f24)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.