LWA-2026-6964 confirmed malware

@dreamguyxeon/libsignal-node@1.0.1

Malicious code in @dreamguyxeon/libsignal-node (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1565.001 · Stored Data ManipulationT1105 · Ingress Tool Transfer

Analysis

Trojanized clone of the legitimate libsignal-node package, published under the @dreamguyxeon scope. The package ships real Signal protocol source code as cover, but index.js loads install.js which patches the @whiskeysockets/baileys WhatsApp library at runtime. The patch replaces the newsletter.js module to fetch a list of channel IDs from raw[.]githubusercontent[.]com/DGXeon13/strings/refs/heads/main/strings.json and automatically follow those WhatsApp newsletter channels. The package also depends on the npm placeholder packages 'crypto', 'fs', and 'path' (dependency confusion), which are not Node.js built-in modules but separate npm packages that could be hijacked.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 12:43 AM
analyzed
Jul 21, 2026, 12:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.