VDB
Sign up

MAL-2026-16103

Malicious code in @neroxkira/vangal-baileys (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6af1543fb92f079191de134bd36dbb64c340928804df8486acf43546e2c6e185) package.json declares `libsignal` with the source `github:RILLYZY/libsignal-node`, an unpinned reference to a third-party GitHub repository with no tag or commit SHA. On `npm install`, npm clones that repository's default branch HEAD and runs any lifecycle scripts contained in it; libsignal-node ships a native addon with build-time scripts. There is no version pin, hash, or integrity check, so whoever controls RILLYZY/libsignal-node controls install-time code execution on every installer of this package. The referenced GitHub account is unrelated to the libsignal upstream (signalapp) and to any publisher identity declared by this package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@neroxkira/vangal-baileys

No fixed version published yet for @neroxkira/vangal-baileys (npm). Pin to a known-safe version or switch to an alternative.

References