VDB
GCVE-110-OSM-2026-12377
GCVE-110-OSM-2026-12377
Advisory PublishedCVSS 8.8/10
package.json declares the `libsignal` dependency as `github:tenka-san/libsignal-node`, a non-registry source pointing at a personal GitHub account with no tag or commit SHA. On `npm install`, npm fetches whatever the default branch's HEAD points to at that moment and runs any lifecycle scripts inside the cloned repo, so the owner of that account controls code that executes on the installer's machine. The account is unrelated to the upstream Baileys/libsignal publishers, and the package's own metadata is inconsistent (homepage and repository fields point at a Telegram URL while the bug tracker points at a different GitHub org, `pou-code/Baileys`), which is consistent with a repackaged Baileys lure rather than a legitimate fork.
ENTRY
engine-requirements.js (install-hook: node ./engine-requirements.js)
- Install Hook Executes Local JS File in package.json
PERSISTENCE
- Startup Persistence in lib/Socket/chats.js: ".profile"
- Startup Persistence in lib/Socket/messages-send.js: ".profile"
DESTINATION
- 1 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/generics.js: "Buffer.from(value?.data || value).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString('base64')"
- Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString('base64')"
- Network Request in lib/Utils/generics.js: "fetch('https:"
- Network Request in lib/Utils/messages-media.js: "request({ hostname: parsedUrl.hostname, port: parsedUrl.port || (parsedUrl.proto..."
OBFUSCATION
- Dynamic Base64 Decoding in lib/Socket/newsletter.js: "Buffer.from(jid, "base64")"
- Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, 'base64')"
- Dynamic Base64 Decoding in lib/Utils/decode-wa-message.js: "Buffer.from(secret, 'base64')"
- Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, 'base64')"
- String Array Obfuscation in lib/Utils/message-composer.js: "[ 'import', 'export', 'from', 'default', 'as', 'const', 'let', 'var', 'function'..."
- String Array Obfuscation in lib/Utils/messages.js: "[ 'break', 'case', 'catch', 'continue', 'debugger', 'default', 'delete', 'do', '..."
- String Array Obfuscation in lib/WABinary/constants.js: "[ '1724', 'profile_picture', '1071', '1314', '1605', '407', '990', '1710', '746'..."
- Decoded Base64 Content in lib/Socket/newsletter.js (x2)
(+5 more)
ADDITIONAL FINDINGS
- Dynamic Code Execution in lib/Utils/message-composer.js: "exec(line)"
PAYLOAD FILES
lib/Socket/newsletter.js (+ lib/Utils/generics.js, lib/Utils/messages-media.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | xzvbailey | all (affected) | — |
Aliases
Browse GCVE Records
264 records in the GCVE database · Updated September 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.