LWA-2026-10107 MAL-2026-13474 ↗ confirmed malware

@diezyyasha/libsignal-node@2.2.8

Malicious code in @diezyyasha/libsignal-node (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1574.002 · DLL Side-LoadingT1078 · Valid Accounts

Analysis

@diezyyasha/libsignal-node@2.2.8 is a trojanized clone of the libsignal-node crypto library. The package ships the genuine libsignal-node source tree but adds an install module that runs when the package is required: it locates the installer's @whiskeysockets/baileys (WhatsApp) package and overwrites lib/Socket/newsletter.js with a modified version. The injected code waits 120 seconds after a Baileys socket is created, then silently issues a newsletter FOLLOW request for the hardcoded channel id 120363407277177688@newsletter using the victim's authenticated WhatsApp session, auto-subscribing the victim's account to that channel without consent. A marker file is written to prevent re-patching. No credentials are exfiltrated; the tampering abuses the victim's own WhatsApp session to inflate a newsletter's follower count.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 10:24 AM
analyzed
Aug 5, 2026, 10:34 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.