@diezyyasha/libsignal-node@2.2.8
Malicious code in @diezyyasha/libsignal-node (npm)
Analysis
@diezyyasha/libsignal-node@2.2.8 is a trojanized clone of the libsignal-node crypto library. The package ships the genuine libsignal-node source tree but adds an install module that runs when the package is required: it locates the installer's @whiskeysockets/baileys (WhatsApp) package and overwrites lib/Socket/newsletter.js with a modified version. The injected code waits 120 seconds after a Baileys socket is created, then silently issues a newsletter FOLLOW request for the hardcoded channel id 120363407277177688@newsletter using the victim's authenticated WhatsApp session, auto-subscribing the victim's account to that channel without consent. A marker file is written to prevent re-patching. No credentials are exfiltrated; the tampering abuses the victim's own WhatsApp session to inflate a newsletter's follower count.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 10:24 AM
- analyzed
- Aug 5, 2026, 10:34 AM
Related advisories
- native-hello-plugin@1.2.0
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
- free-anthropic-claude@5.3.0
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2
- @quantum-ai/gemini-cli@0.45.1
- foodi@99.99.1
- @nasddatax/common@1.0.21
- devpack-conf@5.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.