Malicious code in @dreamguyxeon/libsignal-node (npm)
@dreamguyxeon/libsignal-node is a malicious npm package that patches @whiskeysockets/baileys at import time to inject remote-controlled WhatsApp newsletter auto-follow code. The package was distributed as a dependency alias in my-auto-follow@1.0.3 and is part of a related malicious campaign.
- Disclosed
- Last updated
- Blast radius
- Users of @dreamguyxeon/libsignal-node and downstream consumers via my-auto-follow@1.0.3 dependency chain
- Ecosystems
- Attack vectors
- Affected entities
- @dreamguyxeon/libsignal-nodeMalicious npm package with import-time supply-chain tampering
- @dgxeon13/libsignal-node · 1.0.0Related malicious package with same attack pattern
- my-auto-follow · 1.0.3Package using @dreamguyxeon/libsignal-node as libsignal alias dependency
@dreamguyxeon/libsignal-node is a malicious npm package that performs import-time supply-chain tampering. Upon require, it patches the @whiskeysockets/baileys library's lib/Socket/newsletter.js file with remote-controlled code that automatically follows WhatsApp newsletters without user consent.
The malicious behavior includes fetching configuration from a remote source (DGXeon13/strings) after a 120-second delay and silently executing FOLLOW commands. This package was distributed as a libsignal alias dependency in my-auto-follow@1.0.3, expanding its reach through the dependency chain.
This incident is part of a related malicious campaign that includes @dgxeon13/libsignal-node@1.0.0 (MAL-2025-806) and is tracked under OSV identifier MAL-2026-13931. The package was identified and credited to the OpenSSF malicious-packages project.
The tarball hash (41906336d7a9cbf416ca8ac3e01af4ffad13a1048cd306390734fa18a061ba8c) can be used to verify affected installations.
Indicators of compromise
- Packages
- @dreamguyxeon/libsignal-node
- @dgxeon13/libsignal-node@1.0.0
- my-auto-follow@1.0.3
- Hashes
- 41906336d7a9cbf416ca8ac3e01af4ffad13a1048cd306390734fa18a061ba8c
Remediation
- Immediately remove @dreamguyxeon/libsignal-node from all projects and dependency chains
- Audit all installations of my-auto-follow@1.0.3 and related packages for presence of @dreamguyxeon/libsignal-node
- Verify package integrity using the provided tarball hash (41906336d7a9cbf416ca8ac3e01af4ffad13a1048cd306390734fa18a061ba8c)
- Review WhatsApp account activity for unauthorized newsletter follows if the package was installed
- Update to legitimate libsignal packages from official sources
- Implement dependency scanning and verification in CI/CD pipelines to detect typosquatting and malicious aliases
Sources
- GitHub Advisory GHSA-9v7q-77r5-vfgc · GitHub Advisory Database
Cite this entry
"Malicious code in @dreamguyxeon/libsignal-node (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 13, 2026; last updated August 13, 2026. https://supplychainattack.org/incident/malicious-code-in-dreamguyxeon-libsignal-node-npm-ikq9pj
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit - containedcritical
Malicious code in akamaijs-sensor (npm)
The npm package akamaijs-sensor contained malicious code that executed arbitrary JavaScript via hidden Unicode-encoded bytes and established a command-and-control channel through a Google Calendar dead-drop. The package was designed to run attacker-authored code in the consumer's Node process when the sensor() API was called.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in akamaijs-sensorv1 (npm)
The npm package akamaijs-sensorv1, which advertises itself as an Akamai Bot Manager sensor generator, contains malicious code that executes hidden dynamic code and fetches remote instructions from a Google Calendar-based command-and-control channel. The package uses invisible Unicode characters to conceal executable code and establishes a covert remote-code execution sink controlled by an attacker-owned email account.
npmCompromised packageMalicious commit - containedcritical
Malicious code in @wololasod/tiny-id (npm)
The npm package @wololasod/tiny-id contained obfuscated malicious code that downloads and executes platform-specific remote executables on Windows and Linux systems. The dropper was embedded in both the main entry point (dist/index.cjs) and the TypeScript types file (dist/index.d.ts), disguised as a tiny ID generator.
npmCompromised packageMalicious commit