LWA-2026-6802 confirmed malware

anya-bail@1.1.5

Malicious code in anya-bail (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

anya-bail@1.1.5 is a combosquat of the Baileys WhatsApp Web library that hijacks the 'libsignal' dependency. The package pins libsignal to a tarball URL under the @queenanya npm scope instead of the real libsignal package. When the package imports libsignal for Signal Protocol crypto operations, the attacker-controlled code from @queenanya/libsignal is loaded instead, enabling arbitrary code execution in the cryptographic layer. The package has no repository and the publisher email is a throwaway address.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 06:29 AM
analyzed
Jul 15, 2026, 06:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.