npm
Malicious @openclaw-cn/libsignal @2.1.1
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 3:29 AM UTC
OSV ID
MAL-2026-3843
Ecosystem
npm
Summary
The package @openclaw-cn/libsignal was found to contain malicious code.
Source: amazon-inspector (85fb1bd455a85140d13ec5cb826c0f8c6164c87a6eeacd72f7fc525440b76f24)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.