MAL-2026-13929

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dgxeon13/libsignal-node/MAL-2026-13929.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13929
Published
2026-08-10T22:30:00Z
Modified
2026-08-13T06:30:10.732864415Z
Summary
Malicious code in @dgxeon13/libsignal-node (npm)
Details

npm/@dgxeon13/libsignal-node impersonates Signal's libsignal Node binding. On require of index.js, after a short delay it runs install.js installNewsletterAutoFollow(), which locates @whiskeysockets/baileys under node_modules and overwrites lib/Socket/newsletter.js with an embedded payload that performs remote-controlled consentless WhatsApp newsletter auto-follow (fetch DGXeon13/strings after 120s, silent FOLLOW). This is supply-chain tampering of a third-party package at import time. Distinct from the separately reported @dgxeon/libsignal-node (different npm scope). Used as the libsignal alias from @dreamguyxeon/baileyx. Related campaign OSV: MAL-2026-2252, MAL-2025-806. Tarball sha256: 46e4b9fd62489e1e28c88f8ebac77cf0fa6c48639cd6d548bdb097ca6793d157.

Database specific
{
    "iocs": {
        "urls": [
            "https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json",
            "https://raw.githubusercontent.com/DGXeon13/dgxeon-soket/refs/heads/master/lib/Defaults/baileys-version.json"
        ]
    }
}
References
Credits

Affected packages

npm / @dgxeon13/libsignal-node

Package

Name
@dgxeon13/libsignal-node
View open source insights on deps.dev
Purl
pkg:npm/%40dgxeon13/libsignal-node

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dgxeon13/libsignal-node/MAL-2026-13929.json"