{"id":"MAL-2026-16279","summary":"Malicious code in xzvbailsx (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ac9176da252791a96b93c24e702c2245fb96d9655cdf9f31d61e9bc3e0c21528)\npackage.json declares the dependency `libsignal` with source `github:tenka-san/libsignal-node`, an unpinned GitHub ref with no commit SHA, tag, or integrity hash. On `npm install`, npm fetches whatever HEAD of that repository currently points at and executes any lifecycle scripts (preinstall/install/postinstall) it contains on the installer's machine. The referenced GitHub account is a personal repository unrelated to the WhiskeySockets/Baileys upstream that this package forks. Provenance is further obscured by an identity mismatch: the package is published as `xzvbailsx` but README/examples describe it as `@XzV-RxVz/xbails`, and the `repository` field points to Telegram handles (`t.me/JustRxVz`, `t.me/XzV_ExpzC`) rather than a source repository.\n","modified":"2026-09-18T03:30:06.056760295Z","published":"2026-09-18T02:57:57Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020177","import_time":"2026-09-18T03:21:13.660184036Z","modified_time":"2026-09-18T02:57:57Z","sha256":"ac9176da252791a96b93c24e702c2245fb96d9655cdf9f31d61e9bc3e0c21528"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/xzvbailsx/v/1.0.0"}],"affected":[{"package":{"name":"xzvbailsx","ecosystem":"npm","purl":"pkg:npm/xzvbailsx"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xzvbailsx/MAL-2026-16279.json","indicators":{"package_integrity":[{"filename":"xzvbailsx-1.0.0.tgz","hashes":{"sha1":"7307380d9e56adfd07bfd2454c225e2a69416011","sha512_sri":"sha512-aBX9cMBN7+Bt+OPTTVDOG0pEXXzZjqLRLcXyrwYonDF7SjvxbyEob7ZqQFu8cIWXj5KWzj0Zdt+X706zC/ZV8Q=="}}],"evidence_files":[{"sha256":"2e9a43bc2de0b1b580e4fbe7328188a2134baae3d0dd5e43a83e94c530a647b3","tlsh":"5181ca35ce58ce630ac526e8a9bc0042947559539ec5fc1cb3540bac8f5e15f72b9b3e","path":"package.json"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}