LWA-2026-10990 confirmed malware

@tamago19/tamaaago@2.1.3

Malicious code in @tamago19/tamaaago (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

A WhatsApp API library (Baileys fork) that substitutes its core Signal encryption dependency `libsignal` with a non-standard fork `@shennmine/libsignal-node`, and declares dependencies on the known-malicious packages `@cacheable/node-cache` and `cache-manager`. The package performs network activity during installation. The substituted crypto library and the malicious dependencies are the attack surface; installers of this package inherit the untrusted code.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 03:26 PM
analyzed
Aug 11, 2026, 03:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.