Logo
npm

focaleys@1.1.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 7:13 AM UTC

Malicious

OSV ID

MAL-2026-17329

Ecosystem

npm

Summary

package.json declares the dependency 'libsignal' as 'github:rexxzyid/libsignal-node' with no tag, version, or commit SHA. On npm install, this resolves to whatever the default branch HEAD contains at that moment, with no integrity check, and any lifecycle scripts in the fetched repository execute on the installer's machine. Whoever controls the rexxzyid GitHub account controls code that runs at install time for every installer of focaleys, and the fetched code can change silently between installs without any change to focaleys itself.

Source: amazon-inspector (481093b5037c8aafc763d4543e5a6a39c2ebc7055673eb1d4f480f885593bcd2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.