LWA-2026-5784 MAL-2026-6281 ↗ confirmed malware

libsignal-node-travatiger@1.0.0

Malicious code in libsignal-node-travatiger (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1554 · Compromise Host Software BinaryT1105 · Ingress Tool Transfer

Analysis

libsignal-node-travatiger is a trojanized clone of the legitimate libsignal-node library that targets projects using @whiskeysockets/baileys (WhatsApp Web). On require(), it locates the baileys package in node_modules and patches its newsletter socket to silently auto-follow a list of attacker-controlled WhatsApp channels. The channel list is fetched from raw[.]githubusercontent[.]com/travatiger/MegaTeam/main/channel.json, and auto-following begins 120 seconds after load, processing one channel every 11 seconds.

analyzed by
Leitwacht
first seen
Jun 20, 2026, 07:56 AM
analyzed
Jun 20, 2026, 07:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.