{"id":"MAL-2026-16389","summary":"Malicious code in noverojava (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a7fbf0d1519b05868b34e9e2c1d3588a0596003a5cb53e4cd28fd3a856ecff26)\npackage.json declares the runtime dependency `libsignal` as `github:tenka-san/libsignal-node` rather than a registry version range or pinned commit SHA. On `npm install`, npm fetches the current HEAD of that fork's default branch and executes any lifecycle scripts it defines. The fork is under a third-party GitHub account (not the upstream WhiskeySockets libsignal-node maintainer), has no commit pin, and no integrity check, so whoever controls that account controls code that runs on the installer's machine at install time. The package presents as a Baileys/WhatsApp library fork; the static match on lib/Utils/generics.js line 403 (ping/GET tokens) is consistent with normal Baileys network code and is not independently indicative of exfiltration.\n","modified":"2026-09-22T18:45:05.957848275Z","published":"2026-09-22T18:07:09Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020297","import_time":"2026-09-22T18:23:45.241710518Z","modified_time":"2026-09-22T18:07:23Z","sha256":"4d712fbfd1c2e69c89e7f8f00bfe47b097f18e5b1b603f8d1eb505e70dc80ba0","source":"amazon-inspector","versions":["1.1.0"]},{"id":"IN-MAL-2026-020299","import_time":"2026-09-22T18:23:45.329045934Z","modified_time":"2026-09-22T18:12:09Z","sha256":"a7fbf0d1519b05868b34e9e2c1d3588a0596003a5cb53e4cd28fd3a856ecff26","source":"amazon-inspector","versions":["1.0.9"]},{"source":"amazon-inspector","versions":["1.0.9"],"id":"IN-MAL-2026-020296","import_time":"2026-09-22T18:23:45.20801557Z","modified_time":"2026-09-22T18:07:09Z","sha256":"ddf2122800252802a165ef37901259d97574d8e2f00d3f7c354fac24f2ead971"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/noverojava/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/noverojava/v/1.0.9"}],"affected":[{"package":{"name":"noverojava","ecosystem":"npm","purl":"pkg:npm/noverojava"},"versions":["1.1.0","1.0.9"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/noverojava/MAL-2026-16389.json","indicators":{"package_integrity":[{"filename":"noverojava-1.1.0.tgz","hashes":{"sha1":"ea931f9d73ed826004b919a1323440337828ebbf","sha512_sri":"sha512-vmdEb3awfAs4zSUozx2rNJU74B0CQPcbRMvqWs1amnJ4jeeeH5II+nRQd+YiJXQ1L+Rx8eEYpbwKN0E69znldg=="}}],"evidence_files":[{"path":"package.json","sha256":"f0be2443031924d6f2875a3f71e6fa2a125c834cc7b9c4dcaab1e0578f68f7b5","tlsh":"7e81db34cd18cea30ac626ec99bc0145a4751a539ec1f81cb35c47ac8f0e11f76b9b2e"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}