MAL-2026-16279
Malicious code in xzvbailsx (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ac9176da252791a96b93c24e702c2245fb96d9655cdf9f31d61e9bc3e0c21528) package.json declares the dependency `libsignal` with source `github:tenka-san/libsignal-node`, an unpinned GitHub ref with no commit SHA, tag, or integrity hash. On `npm install`, npm fetches whatever HEAD of that repository currently points at and executes any lifecycle scripts (preinstall/install/postinstall) it contains on the installer's machine. The referenced GitHub account is a personal repository unrelated to the WhiskeySockets/Baileys upstream that this package forks. Provenance is further obscured by an identity mismatch: the package is published as `xzvbailsx` but README/examples describe it as `@XzV-RxVz/xbails`, and the `repository` field points to Telegram handles (`t.me/JustRxVz`, `t.me/XzV_ExpzC`) rather than a source repository.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for xzvbailsx (npm). Pin to a known-safe version or switch to an alternative.