@dilxzphrine/libsignal-node@2.5.0
Malicious code in @dilxzphrine/libsignal-node (npm)
Analysis
Combosquat package @dilxzphrine/libsignal-node impersonates the Signal protocol library but silently patches the @whiskeysockets/baileys WhatsApp library at runtime. On require(), index.js schedules a payload that overwrites baileys/lib/Socket/newsletter.js with a modified version. The modified code auto-follows two hardcoded WhatsApp newsletter JIDs (120363330289360382@newsletter and 120363409782361079@newsletter) via WhatsApp's w:mex query infrastructure whenever the WhatsApp socket is initialized. A .cache marker file is written into the baileys node_modules directory to ensure the patch only executes once. The attacker's goal is to inflate newsletter follower counts through victims' WhatsApp credentials. The legitimate Signal protocol source files (src/crypto.js etc.) are shipped as a decoy.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 06:58 PM
- analyzed
- Jun 15, 2026, 06:59 PM
Related advisories
- @dilxzphrine/baileys@1.0.0
- @sfhbdrffthger/boardstep@1.0.0
- vite-config-field@1.1.0
- dms-backend@1.0.0
- ts-webplug@3.0.5
- tsliverhome@1.1.5
- trgrip@1.0.4
- transform-es2015-destructuring@6.24.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.