LWA-2026-11362 confirmed malware

libas-signal@1.0.0

Malicious code in libas-signal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1574 · Hijack Execution FlowT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

When required, this package silently locates the victim's installed @whiskeysockets/baileys (WhatsApp) library and overwrites its lib/Socket/newsletter.js with a modified copy. The injected code waits 120 seconds, then uses the victim's authenticated WhatsApp session to follow a hardcoded newsletter channel (120363407277177688@newsletter), inflating that channel's subscriber count. It writes a marker cache file and terminates the process to hide the tampering. The package also declares the Node core modules crypto, fs, and path as npm dependencies.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 03:43 AM
analyzed
Aug 16, 2026, 03:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.