{"id":"MAL-2026-16103","summary":"Malicious code in @neroxkira/vangal-baileys (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6af1543fb92f079191de134bd36dbb64c340928804df8486acf43546e2c6e185)\npackage.json declares `libsignal` with the source `github:RILLYZY/libsignal-node`, an unpinned reference to a third-party GitHub repository with no tag or commit SHA. On `npm install`, npm clones that repository's default branch HEAD and runs any lifecycle scripts contained in it; libsignal-node ships a native addon with build-time scripts. There is no version pin, hash, or integrity check, so whoever controls RILLYZY/libsignal-node controls install-time code execution on every installer of this package. The referenced GitHub account is unrelated to the libsignal upstream (signalapp) and to any publisher identity declared by this package.\n","modified":"2026-09-09T22:45:18.793451183Z","published":"2026-09-09T22:27:01Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-09T22:27:17Z","sha256":"6af1543fb92f079191de134bd36dbb64c340928804df8486acf43546e2c6e185","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019905","import_time":"2026-09-09T22:38:09.725814624Z"},{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-019903","import_time":"2026-09-09T22:38:09.627391261Z","modified_time":"2026-09-09T22:27:01Z","sha256":"eb3ff3a1de60af948c4f2ec5e981b6d2e372d9d9ac580302b0fa8cb7037a679e"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@neroxkira/vangal-baileys/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@neroxkira/vangal-baileys/v/1.0.1"}],"affected":[{"package":{"name":"@neroxkira/vangal-baileys","ecosystem":"npm","purl":"pkg:npm/%40neroxkira/vangal-baileys"},"versions":["1.0.0","1.0.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"2420f5e1d14ddbed43d315fb141e02b77662af7cebe277dc56176b257f2aa3b4","tlsh":"7661fb23cd4cce3308f673e9b9b54201f468435f2240c85f323c4bac4f7369a2045a29"}],"package_integrity":[{"hashes":{"sha1":"769cfc19026ef6cdc1347477a2a3efc6d4e1db69","sha512_sri":"sha512-ZSpy1ink+HX4sfmr7MTv1bHibIzVVz6b+ItKRKLh6aAc3vhD2WPDbnx6AXhekhDz46Y3S79zJmpXPHxf6IgS7A=="},"filename":"vangal-baileys-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@neroxkira/vangal-baileys/MAL-2026-16103.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}