LWA-2026-11362 confirmed malware
libas-signal@1.0.0
Malicious code in libas-signal (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1574 · Hijack Execution FlowT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
When required, this package silently locates the victim's installed @whiskeysockets/baileys (WhatsApp) library and overwrites its lib/Socket/newsletter.js with a modified copy. The injected code waits 120 seconds, then uses the victim's authenticated WhatsApp session to follow a hardcoded newsletter channel (120363407277177688@newsletter), inflating that channel's subscriber count. It writes a marker cache file and terminates the process to hide the tampering. The package also declares the Node core modules crypto, fs, and path as npm dependencies.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 03:43 AM
- analyzed
- Aug 16, 2026, 03:44 AM
Related advisories
- tyepescript-core@1.0.0
- typescriptt-core@1.0.0
- comander-lib@1.0.0
- typesript-core@1.0.0
- raectjs@1.0.0
- typscript-core@1.0.0
- typescirpt-cli@1.0.0
- typescipt-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.