LWA-2026-10990 confirmed malware
@tamago19/tamaaago@2.1.3
Malicious code in @tamago19/tamaaago (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
A WhatsApp API library (Baileys fork) that substitutes its core Signal encryption dependency `libsignal` with a non-standard fork `@shennmine/libsignal-node`, and declares dependencies on the known-malicious packages `@cacheable/node-cache` and `cache-manager`. The package performs network activity during installation. The substituted crypto library and the malicious dependencies are the attack surface; installers of this package inherit the untrusted code.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 03:26 PM
- analyzed
- Aug 11, 2026, 03:28 PM
Related advisories
- neverthrow-core@1.1.2
- kit-vim-map@1.0.0
- @sqlite-labs-free/createsql@1.0.5
- freeai-proxy@1.0.0
- vexium-kit@2.0.2
- process-live-log@11.5.2
- @sqlite-labs/nodesql@1.0.5
- safe-local-env-loader@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.