@dreamguyxeon/libsignal-node@1.0.1
Malicious code in @dreamguyxeon/libsignal-node (npm)
Analysis
Trojanized clone of the legitimate libsignal-node package, published under the @dreamguyxeon scope. The package ships real Signal protocol source code as cover, but index.js loads install.js which patches the @whiskeysockets/baileys WhatsApp library at runtime. The patch replaces the newsletter.js module to fetch a list of channel IDs from raw[.]githubusercontent[.]com/DGXeon13/strings/refs/heads/main/strings.json and automatically follow those WhatsApp newsletter channels. The package also depends on the npm placeholder packages 'crypto', 'fs', and 'path' (dependency confusion), which are not Node.js built-in modules but separate npm packages that could be hijacked.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 12:43 AM
- analyzed
- Jul 21, 2026, 12:44 AM
Related advisories
- ordered-btree@3.2.2
- @sauruslord/libsignal@2.0.2
- topk-js@0.12.0
- json-validator-utils@1.0.1
- habingeer@2.1.6
- tailwind-animationfound@2.3.7
- ts-vitest@1.1.1
- n8n-nodes-probe@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.