-= Per source details. Do not edit below this line.=-
package.json declares the libsignal dependency as github:canove/libsignal-node — a bare GitHub owner/repo reference with no commit SHA, tag, or semver version. On npm install, this resolves to whatever the current HEAD of that third-party repository points at, fetching and installing arbitrary code with no integrity check and running any lifecycle scripts inside the returned bytes. Whoever controls that GitHub repository at any future moment controls code executed on every installer of this package. The static ping/GET co-occurrence in lib/Utils/generics.js is unrelated to this finding.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020172",
"import_time": "2026-09-18T02:25:26.308382622Z",
"modified_time": "2026-09-18T01:40:17Z",
"sha256": "2cd9141ef0d6d97338c5f976c8071a6f5c37010683b27d4463b2221d76b82304",
"source": "amazon-inspector",
"versions": [
"0.0.1"
]
},
{
"id": "IN-MAL-2026-020316",
"import_time": "2026-09-22T23:15:45.005930018Z",
"modified_time": "2026-09-22T23:07:14Z",
"sha256": "da5caafea4a5656343feb4b52bf0007c98e6ed65a41ad22c79f24c0f1c48566f",
"source": "amazon-inspector",
"versions": [
"0.0.7"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "5a0b91acbb96e44456dc68599be20adf19201f573e9f51a98eddf8f0f630e0d4",
"tlsh": "b991b974cd59cea30a8626ed99bc0141a4b556539ec2f81cb31c07ac8f5e24fb1b9b3d"
}
],
"package_integrity": [
{
"filename": "baileys-0.0.1.tgz",
"hashes": {
"sha1": "069ad2b5c1122d2cfb91b34e9ab2ef7392bb5933",
"sha512_sri": "sha512-nCNkVnTqxuKKMjjDgPW084P2/z70n1+1gL3s52LIlAidfRPxtV5EQJ3HLkOHfXP3VDcTShhQgOr1PV6rp3f1RA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@lekzo/baileys/MAL-2026-16276.json"