LWA-2026-6802 confirmed malware
anya-bail@1.1.5
Malicious code in anya-bail (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
anya-bail@1.1.5 is a combosquat of the Baileys WhatsApp Web library that hijacks the 'libsignal' dependency. The package pins libsignal to a tarball URL under the @queenanya npm scope instead of the real libsignal package. When the package imports libsignal for Signal Protocol crypto operations, the attacker-controlled code from @queenanya/libsignal is loaded instead, enabling arbitrary code execution in the cryptographic layer. The package has no repository and the publisher email is a throwaway address.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 06:29 AM
- analyzed
- Jul 15, 2026, 06:30 AM
Related advisories
- react-hook-doms@5.3.1
- @debile/require-dir@1.9.1
- npmresearch2026-prov-test@1.0.0
- assertion-utils-js@2.4.3
- smb-common-uikit@15.2.0
- ahooks-3.7.8@13.1.1
- cppt-common@13.1.1
- @risaoffc/baileys@8.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.