xzvbailsx@1.0.0
Vulnerability report · Last retrieved from osv.dev September 18, 2026 at 6:39 AM UTC
OSV ID
MAL-2026-16279
Ecosystem
npm
Summary
package.json declares the dependency libsignal with source github:tenka-san/libsignal-node, an unpinned GitHub ref with no commit SHA, tag, or integrity hash. On npm install, npm fetches whatever HEAD of that repository currently points at and executes any lifecycle scripts (preinstall/install/postinstall) it contains on the installer's machine. The referenced GitHub account is a personal repository unrelated to the WhiskeySockets/Baileys upstream that this package forks. Provenance is further obscured by an identity mismatch: the package is published as xzvbailsx but README/examples describe it as @XzV-RxVz/xbails, and the repository field points to Telegram handles (t.me/JustRxVz, t.me/XzV_ExpzC) rather than a source repository.
Source: amazon-inspector (ac9176da252791a96b93c24e702c2245fb96d9655cdf9f31d61e9bc3e0c21528)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.