MAL-2026-16389

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/noverojava/MAL-2026-16389.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16389
Published
2026-09-22T18:07:09Z
Modified
2026-09-22T18:45:05Z
Summary
Malicious code in noverojava (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a7fbf0d1519b05868b34e9e2c1d3588a0596003a5cb53e4cd28fd3a856ecff26)

package.json declares the runtime dependency libsignal as github:tenka-san/libsignal-node rather than a registry version range or pinned commit SHA. On npm install, npm fetches the current HEAD of that fork's default branch and executes any lifecycle scripts it defines. The fork is under a third-party GitHub account (not the upstream WhiskeySockets libsignal-node maintainer), has no commit pin, and no integrity check, so whoever controls that account controls code that runs on the installer's machine at install time. The package presents as a Baileys/WhatsApp library fork; the static match on lib/Utils/generics.js line 403 (ping/GET tokens) is consistent with normal Baileys network code and is not independently indicative of exfiltration.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020297",
            "import_time":  "2026-09-22T18:23:45.241710518Z",
            "modified_time":  "2026-09-22T18:07:23Z",
            "sha256":  "4d712fbfd1c2e69c89e7f8f00bfe47b097f18e5b1b603f8d1eb505e70dc80ba0",
            "source":  "amazon-inspector",
            "versions":  [
                "1.1.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020299",
            "import_time":  "2026-09-22T18:23:45.329045934Z",
            "modified_time":  "2026-09-22T18:12:09Z",
            "sha256":  "a7fbf0d1519b05868b34e9e2c1d3588a0596003a5cb53e4cd28fd3a856ecff26",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.9"
            ]
        },
        {
            "id":  "IN-MAL-2026-020296",
            "import_time":  "2026-09-22T18:23:45.20801557Z",
            "modified_time":  "2026-09-22T18:07:09Z",
            "sha256":  "ddf2122800252802a165ef37901259d97574d8e2f00d3f7c354fac24f2ead971",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.9"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / noverojava

Package

Affected ranges

Affected versions

1.*
1.0.9
1.1.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "f0be2443031924d6f2875a3f71e6fa2a125c834cc7b9c4dcaab1e0578f68f7b5",
            "tlsh":  "7e81db34cd18cea30ac626ec99bc0145a4751a539ec1f81cb35c47ac8f0e11f76b9b2e"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "noverojava-1.1.0.tgz",
            "hashes":  {
                "sha1":  "ea931f9d73ed826004b919a1323440337828ebbf",
                "sha512_sri":  "sha512-vmdEb3awfAs4zSUozx2rNJU74B0CQPcbRMvqWs1amnJ4jeeeH5II+nRQd+YiJXQ1L+Rx8eEYpbwKN0E69znldg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/noverojava/MAL-2026-16389.json"