@vinnxcode/libsignal-node @1.0.1
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-11079
Ecosystem
npm
Summary
Analysis of this package version surfaced no a static rule matches and no traced install-time or import-time behaviors indicating credential theft, exfiltration, dropper execution, silent-relay, backdoor, or self-propagation. The package name suggests a fork or re-publish of the libsignal-node Signal Protocol library under a personal scope; without concrete evidence of installer-harm mechanisms in the shipped code, no supply-chain attack fingerprint is present in this version.
Source: amazon-inspector (92b886dd14e44e2d8c35f297283b6bf7eb3cc0e947d786130c5fd8976d7ebdc1)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.