MAL-2026-13931

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dreamguyxeon/libsignal-node/MAL-2026-13931.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13931
Published
2026-08-10T22:30:00Z
Modified
2026-09-29T22:31:17Z
Summary
Malicious code in @dreamguyxeon/libsignal-node (npm)
Details

npm/@dreamguyxeon/libsignal-node has the same import-time supply-chain tampering as @dgxeon13/libsignal-node@1.0.0: on require it patches @whiskeysockets/baileys lib/Socket/newsletter.js with remote-controlled consentless WhatsApp newsletter auto-follow code (fetch DGXeon13/strings after 120s, silent FOLLOW). Used as the libsignal npm alias dependency from my-auto-follow@1.0.3. Related campaign OSV: MAL-2026-2252, MAL-2025-806. Tarball sha256: 41906336d7a9cbf416ca8ac3e01af4ffad13a1048cd306390734fa18a061ba8c.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4a3df23ac106ff1cebc25aade4a3e3cc3da77bc493c20b2e0b37e90807f51ea1)

Package is published as a Signal protocol implementation but its shipped code has no Signal functionality. index.js schedules install.js one second after require(). install.js locates the installer's @whiskeysockets/baileys module and overwrites lib/Socket/newsletter.js with an embedded replacement, drops a marker file at baileys/node_modules/.cache containing 'Iove' to make the tamper persistent and idempotent, and forces process.exit(0) 20 seconds later, abruptly terminating the host process. The replacement newsletter.js fetches https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json (a personal GitHub repo, mutable main branch) and iterates the returned IDs to call newsletterWMexQuery(id, QueryIds.FOLLOW), causing the installer's authenticated WhatsApp session to follow attacker-chosen channels. Because the injected file is a full rewrite of the dependency's source and the remote list is mutable and unauthenticated, the author retains the ability to change the JSON at any time to drive arbitrary newsletter operations on every installer's WhatsApp account, and could substitute more damaging behavior into the rewritten newsletter.js path.

Database specific
{
    "iocs": {
        "urls": [
            "https://raw.githubusercontent.com/DGXeon13/strings/refs/heads/main/strings.json",
            "https://raw.githubusercontent.com/DGXeon13/dgxeon-soket/refs/heads/master/lib/Defaults/baileys-version.json"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020678",
            "import_time": "2026-09-29T22:18:23.615535949Z",
            "modified_time": "2026-09-29T21:42:23Z",
            "sha256": "0262bf864e58dc456bedf22a92b15de7c4a4f36e978c241f5ab292a9222efcd1",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-020675",
            "import_time": "2026-09-29T22:18:23.442487645Z",
            "modified_time": "2026-09-29T21:41:55Z",
            "sha256": "4a3df23ac106ff1cebc25aade4a3e3cc3da77bc493c20b2e0b37e90807f51ea1",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "id": "IN-MAL-2026-020674",
            "import_time": "2026-09-29T22:18:23.366285874Z",
            "modified_time": "2026-09-29T21:41:45Z",
            "sha256": "e7dd8fe487ca717b2212f49263e1ccb90dbe89e9e4dfb9b6b9eb80f3814df694",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @dreamguyxeon/libsignal-node

Package

Name
@dreamguyxeon/libsignal-node
View open source insights on deps.dev
Purl
pkg:npm/%40dreamguyxeon/libsignal-node

Affected ranges

Affected versions

1.*
1.0.1
1.0.2
1.0.3

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "install.js",
            "sha256": "fddaa11e074f9657118d3b79b6da501e4e34d2105667dd89ba81d5c651a2549c",
            "tlsh": "f682964755fa577a07a37454a62f7090b321f2837629dd653f8c91020f8a2dcade3b98"
        },
        {
            "path": "package.json",
            "sha256": "57c2772b9f24d8eb997cbf0f1801b975afb8b8696f33d6154021942fc54c8757",
            "tlsh": "49f02421ca149c3300c47e266c354917a3a20c6345597d0c33cad50c8f9e11f22be66c"
        }
    ],
    "package_integrity": [
        {
            "filename": "libsignal-node-1.0.1.tgz",
            "hashes": {
                "sha1": "a83900702f64ca139397bc076dd35f27fbab1951",
                "sha512_sri": "sha512-l+7MkDLSxjrunFqDBGnaZXPLMAq7qEPgqQr/FeDfu1Pj76XiA7s8KOO1Aoqi2tcjhDUprRwVZLCyF2I8/DF3AA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dreamguyxeon/libsignal-node/MAL-2026-13931.json"