MAL-2026-16103

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@neroxkira/vangal-baileys/MAL-2026-16103.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16103
Published
2026-09-09T22:27:01Z
Modified
2026-09-09T22:45:18Z
Summary
Malicious code in @neroxkira/vangal-baileys (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6af1543fb92f079191de134bd36dbb64c340928804df8486acf43546e2c6e185)

package.json declares libsignal with the source github:RILLYZY/libsignal-node, an unpinned reference to a third-party GitHub repository with no tag or commit SHA. On npm install, npm clones that repository's default branch HEAD and runs any lifecycle scripts contained in it; libsignal-node ships a native addon with build-time scripts. There is no version pin, hash, or integrity check, so whoever controls RILLYZY/libsignal-node controls install-time code execution on every installer of this package. The referenced GitHub account is unrelated to the libsignal upstream (signalapp) and to any publisher identity declared by this package.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-019905",
            "import_time": "2026-09-09T22:38:09.725814624Z",
            "modified_time": "2026-09-09T22:27:17Z",
            "sha256": "6af1543fb92f079191de134bd36dbb64c340928804df8486acf43546e2c6e185",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-019903",
            "import_time": "2026-09-09T22:38:09.627391261Z",
            "modified_time": "2026-09-09T22:27:01Z",
            "sha256": "eb3ff3a1de60af948c4f2ec5e981b6d2e372d9d9ac580302b0fa8cb7037a679e",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @neroxkira/vangal-baileys

Package

Name
@neroxkira/vangal-baileys
View open source insights on deps.dev
Purl
pkg:npm/%40neroxkira/vangal-baileys

Affected ranges

Affected versions

1.*
1.0.0
1.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "2420f5e1d14ddbed43d315fb141e02b77662af7cebe277dc56176b257f2aa3b4",
            "tlsh": "7661fb23cd4cce3308f673e9b9b54201f468435f2240c85f323c4bac4f7369a2045a29"
        }
    ],
    "package_integrity": [
        {
            "filename": "vangal-baileys-1.0.0.tgz",
            "hashes": {
                "sha1": "769cfc19026ef6cdc1347477a2a3efc6d4e1db69",
                "sha512_sri": "sha512-ZSpy1ink+HX4sfmr7MTv1bHibIzVVz6b+ItKRKLh6aAc3vhD2WPDbnx6AXhekhDz46Y3S79zJmpXPHxf6IgS7A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@neroxkira/vangal-baileys/MAL-2026-16103.json"