@sauruslord/libsignal@2.0.2
Malicious code in @sauruslord/libsignal (npm)
Analysis
@sauruslord/libsignal@2.0.2 is a combosquat of the Signal Protocol library that performs runtime code injection. At require(), index.js schedules install.js's installNewsletterAutoFollow() which (1) searches for @whiskeysockets/baileys in the project's node_modules, (2) overwrites baileys/lib/Socket/newsletter.js with a malicious replacement that forces the WhatsApp client to auto-follow hardcoded newsletter 120363425694844039@newsletter, and (3) calls process.exit(0) after 20s to restart. The package also declares Node.js core modules (crypto, fs, path) as npm dependencies — a red flag pattern since no legitimate libsignal would shadow built-in modules. No token theft observed, but this is a code-injection supply-chain attack modifying files in another installed package at runtime without user consent.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 07:59 PM
- analyzed
- Jun 10, 2026, 08:00 PM
Related advisories
- @dreamguyxeon/libsignal-node@1.0.1
- ordered-btree@3.2.2
- mongoose-lean-hooks@0.5.2
- fastify-addon@5.1.0
- modulyn@1.0.1
- mm-ts-utils-client@99.9.1
- mkt-ui-library@45.0.0
- mjs-biginteger@5.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.