{"id":"MAL-2026-4443","summary":"Malicious code in @shinzepelly/libsignal-node (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (957954ced5e6fb2e8ab6a666adf496ca2edc7575a4e202b593d6698b5d89809f)\nPackage impersonates the legitimate libsignal-node library (description copied verbatim: \"Open Whisper Systems' libsignal for Node.js\") under an unrelated scope. On require(), index.js schedules install.js, which overwrites `node_modules/@whiskeysockets/baileys/lib/Socket/newsletter.js` with an attacker-supplied replacement and writes a marker file `.cache` containing 'Iove' to suppress re-patching. The injected newsletter.js, on a 120-second delay at runtime, fetches `https://raw.githubusercontent.com/zelxopz/idnews-ch/refs/heads/main/news.json` (mutable branch, personal GitHub account unrelated to baileys or libsignal) and iterates the returned IDs to call `newsletterWMexQuery(id, QueryIds.FOLLOW)` on the installer's authenticated WhatsApp session, retrying every 11 seconds. After patching, install.js calls `process.exit(0)` 20 seconds later to terminate the host process so the patched module is loaded fresh on next start. Net effect: the installer's WhatsApp identity is silently weaponized to follow attacker-controlled newsletter channels chosen by editing a single JSON file in the attacker's repo, the installer's other installed dependency is corrupted on disk, and the host process is forcibly killed.\n","modified":"2026-05-27T00:31:58.121066842Z","published":"2026-05-20T01:18:55Z","withdrawn":"2026-05-26T20:55:39Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-003354","import_time":"2026-05-26T05:50:28.917541509Z","modified_time":"2026-05-20T01:18:55Z","sha256":"957954ced5e6fb2e8ab6a666adf496ca2edc7575a4e202b593d6698b5d89809f","source":"amazon-inspector","versions":["2.2.4"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@shinzepelly/libsignal-node/v/2.2.4"}],"affected":[{"package":{"name":"@shinzepelly/libsignal-node","ecosystem":"npm","purl":"pkg:npm/%40shinzepelly%2Flibsignal-node"},"versions":["2.2.4"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"2c72b39665fb67a917a37054a67fb0e0b324f243751598627f8c90020f4a2dce8f3bd8","path":"install.js","sha256":"26814e382b0df5bd25177d75ad3449eee30cd79e5f7fa33f5312376afe07dfb8"},{"tlsh":"9af0f020cd259d3341c87a6a6c31084653a21c634994bd0c37ca940c8fae19f22bea6d","path":"package.json","sha256":"61218213824c6fa703870f749a99544905aef604bb71424abb0cdf840b8e2d6c"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-yeJbN4ZDYU6Xr4GeWI1nbdeYrKk1Yk/58W/hST0xgeiZGHGvPWsubXNnvD2o6HMP7yGi6wdldSmDWYr0H9Z6zw==","sha1":"1c4ca8c861a03fa512fc4160cfbf450f1a13214e"},"filename":"libsignal-node-2.2.4.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@shinzepelly/libsignal-node/MAL-2026-4443.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}