libsignal-node-travatiger@1.0.0
Malicious code in libsignal-node-travatiger (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1554 · Compromise Host Software BinaryT1105 · Ingress Tool Transfer
Analysis
libsignal-node-travatiger is a trojanized clone of the legitimate libsignal-node library that targets projects using @whiskeysockets/baileys (WhatsApp Web). On require(), it locates the baileys package in node_modules and patches its newsletter socket to silently auto-follow a list of attacker-controlled WhatsApp channels. The channel list is fetched from raw[.]githubusercontent[.]com/travatiger/MegaTeam/main/channel.json, and auto-following begins 120 seconds after load, processing one channel every 11 seconds.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 07:56 AM
- analyzed
- Jun 20, 2026, 07:57 AM
Related advisories
- kisama-js@0.1.8
- vitest-cli@1.0.0
- react-check-error@2.1.6
- chai-as-uphelded@6.11.4
- chai-as-forgeted@9.24.6
- ts-escro@0.0.6
- panrouter@5.0.0
- panrouter-admin@5.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.