Vulnerability MAL-2026-13931

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 10, 2026 at 10:30 PM UTC
Malicious code in @dreamguyxeon/libsignal-node (npm)
1.0.1 - 1.0.3
1.0.1 - 1.0.3

Summary

Malicious code in @dreamguyxeon/libsignal-node (npm)

Details

npm/@dreamguyxeon/libsignal-node has the same import-time supply-chain tampering as @dgxeon13/[email protected]: on require it patches @whiskeysockets/baileys lib/Socket/newsletter.js with remote-controlled consentless WhatsApp newsletter auto-follow code (fetch DGXeon13/strings after 120s, silent FOLLOW). Used as the libsignal npm alias dependency from [email protected]. Related campaign OSV: MAL-2026-2252, MAL-2025-806. Tarball sha256: 41906336d7a9cbf416ca8ac3e01af4ffad13a1048cd306390734fa18a061ba8c.

Timeline

Published
1 month ago
August 10, 2026 at 10:30 PM UTC
Last Modified
2 hours ago
September 29, 2026 at 10:31 PM UTC