MAL-2026-16103

    Dashboard / Malicious Package / MAL-2026-16103

    MAL-2026-16103

    Published: 9 Sept 2026Last Modified: 9 Sept 2026

    Summary: Malicious code in @neroxkira/vangal-baileys (npm)

    Details: Source: amazon-inspector (6af1543fb92f079191de134bd36dbb64c340928804df8486acf43546e2c6e185) package.json declares `libsignal` with the source `github:RILLYZY/libsignal-node`, an unpinned reference to a third-party GitHub repository with no tag or commit SHA. On `npm install`, npm clones that repository's default branch HEAD and runs any lifecycle scripts contained in it; libsignal-node ships a native addon with build-time scripts. There is no version pin, hash, or integrity check, so whoever controls RILLYZY/libsignal-node controls install-time code execution on every installer of this package. The referenced GitHub account is unrelated to the libsignal upstream (signalapp) and to any publisher identity declared by this package.

    Affected packages

    Package

    Name: @neroxkira/vangal-baileys

    Purl: pkg:npm/%40neroxkira/vangal-baileys

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    1.0.1