-= Per source details. Do not edit below this line.=-
package.json declares libsignal with the source github:RILLYZY/libsignal-node, an unpinned reference to a third-party GitHub repository with no tag or commit SHA. On npm install, npm clones that repository's default branch HEAD and runs any lifecycle scripts contained in it; libsignal-node ships a native addon with build-time scripts. There is no version pin, hash, or integrity check, so whoever controls RILLYZY/libsignal-node controls install-time code execution on every installer of this package. The referenced GitHub account is unrelated to the libsignal upstream (signalapp) and to any publisher identity declared by this package.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-019905",
"import_time": "2026-09-09T22:38:09.725814624Z",
"modified_time": "2026-09-09T22:27:17Z",
"sha256": "6af1543fb92f079191de134bd36dbb64c340928804df8486acf43546e2c6e185",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-019903",
"import_time": "2026-09-09T22:38:09.627391261Z",
"modified_time": "2026-09-09T22:27:01Z",
"sha256": "eb3ff3a1de60af948c4f2ec5e981b6d2e372d9d9ac580302b0fa8cb7037a679e",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "2420f5e1d14ddbed43d315fb141e02b77662af7cebe277dc56176b257f2aa3b4",
"tlsh": "7661fb23cd4cce3308f673e9b9b54201f468435f2240c85f323c4bac4f7369a2045a29"
}
],
"package_integrity": [
{
"filename": "vangal-baileys-1.0.0.tgz",
"hashes": {
"sha1": "769cfc19026ef6cdc1347477a2a3efc6d4e1db69",
"sha512_sri": "sha512-ZSpy1ink+HX4sfmr7MTv1bHibIzVVz6b+ItKRKLh6aAc3vhD2WPDbnx6AXhekhDz46Y3S79zJmpXPHxf6IgS7A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@neroxkira/vangal-baileys/MAL-2026-16103.json"