LWA-2026-5414 confirmed malware

@dilxzphrine/libsignal-node@2.5.0

Malicious code in @dilxzphrine/libsignal-node (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1071.001 · Web Protocols

Analysis

Combosquat package @dilxzphrine/libsignal-node impersonates the Signal protocol library but silently patches the @whiskeysockets/baileys WhatsApp library at runtime. On require(), index.js schedules a payload that overwrites baileys/lib/Socket/newsletter.js with a modified version. The modified code auto-follows two hardcoded WhatsApp newsletter JIDs (120363330289360382@newsletter and 120363409782361079@newsletter) via WhatsApp's w:mex query infrastructure whenever the WhatsApp socket is initialized. A .cache marker file is written into the baileys node_modules directory to ensure the patch only executes once. The attacker's goal is to inflate newsletter follower counts through victims' WhatsApp credentials. The legitimate Signal protocol source files (src/crypto.js etc.) are shipped as a decoy.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 06:58 PM
analyzed
Jun 15, 2026, 06:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.