npm/@dreamguyxeon/libsignal-node has the same import-time supply-chain tampering as @dgxeon13/libsignal-node@1.0.0: on require it patches @whiskeysockets/baileys lib/Socket/newsletter.js with remote-controlled consentless WhatsApp newsletter auto-follow code (fetch DGXeon13/strings after 120s, silent FOLLOW). Used as the libsignal npm alias dependency from my-auto-follow@1.0.3. Related campaign OSV: MAL-2026-2252, MAL-2025-806. Tarball sha256: 41906336d7a9cbf416ca8ac3e01af4ffad13a1048cd306390734fa18a061ba8c.
-= Per source details. Do not edit below this line.=-
Package is published as a Signal protocol implementation but its shipped code has no Signal functionality. index.js schedules install.js one second after require(). install.js locates the installer's @whiskeysockets/baileys module and overwrites lib/Socket/newsletter.js with an embedded replacement, drops a marker file at baileys/node_modules/.cache containing 'Iove' to make the tamper persistent and idempotent, and forces process.exit(0) 20 seconds later, abruptly terminating the host process. The replacement newsletter.js fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json (a personal GitHub repo, mutable main branch) and iterates the returned IDs to call newsletterWMexQuery(id, QueryIds.FOLLOW), causing the installer's authenticated WhatsApp session to follow attacker-chosen channels. Because the injected file is a full rewrite of the dependency's source and the remote list is mutable and unauthenticated, the author retains the ability to change the JSON at any time to drive arbitrary newsletter operations on every installer's WhatsApp account, and could substitute more damaging behavior into the rewritten newsletter.js path.
{
"iocs": {
"urls": [
"https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json",
"https://raw.githubusercontent.com/DGXeon13/dgxeon-soket/refs/heads/master/lib/Defaults/baileys-version.json"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020678",
"import_time": "2026-09-29T22:18:23.615535949Z",
"modified_time": "2026-09-29T21:42:23Z",
"sha256": "0262bf864e58dc456bedf22a92b15de7c4a4f36e978c241f5ab292a9222efcd1",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-020675",
"import_time": "2026-09-29T22:18:23.442487645Z",
"modified_time": "2026-09-29T21:41:55Z",
"sha256": "4a3df23ac106ff1cebc25aade4a3e3cc3da77bc493c20b2e0b37e90807f51ea1",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-020674",
"import_time": "2026-09-29T22:18:23.366285874Z",
"modified_time": "2026-09-29T21:41:45Z",
"sha256": "e7dd8fe487ca717b2212f49263e1ccb90dbe89e9e4dfb9b6b9eb80f3814df694",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "install.js",
"sha256": "fddaa11e074f9657118d3b79b6da501e4e34d2105667dd89ba81d5c651a2549c",
"tlsh": "f682964755fa577a07a37454a62f7090b321f2837629dd653f8c91020f8a2dcade3b98"
},
{
"path": "package.json",
"sha256": "57c2772b9f24d8eb997cbf0f1801b975afb8b8696f33d6154021942fc54c8757",
"tlsh": "49f02421ca149c3300c47e266c354917a3a20c6345597d0c33cad50c8f9e11f22be66c"
}
],
"package_integrity": [
{
"filename": "libsignal-node-1.0.1.tgz",
"hashes": {
"sha1": "a83900702f64ca139397bc076dd35f27fbab1951",
"sha512_sri": "sha512-l+7MkDLSxjrunFqDBGnaZXPLMAq7qEPgqQr/FeDfu1Pj76XiA7s8KOO1Aoqi2tcjhDUprRwVZLCyF2I8/DF3AA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dreamguyxeon/libsignal-node/MAL-2026-13931.json"