VDB

GCVE-110-OSM-2026-12377

GCVE-110-OSM-2026-12377
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 18, 2026
package.json declares the `libsignal` dependency as `github:tenka-san/libsignal-node`, a non-registry source pointing at a personal GitHub account with no tag or commit SHA. On `npm install`, npm fetches whatever the default branch's HEAD points to at that moment and runs any lifecycle scripts inside the cloned repo, so the owner of that account controls code that executes on the installer's machine. The account is unrelated to the upstream Baileys/libsignal publishers, and the package's own metadata is inconsistent (homepage and repository fields point at a Telegram URL while the bug tracker points at a different GitHub org, `pou-code/Baileys`), which is consistent with a repackaged Baileys lure rather than a legitimate fork. ENTRY engine-requirements.js (install-hook: node ./engine-requirements.js) - Install Hook Executes Local JS File in package.json PERSISTENCE - Startup Persistence in lib/Socket/chats.js: ".profile" - Startup Persistence in lib/Socket/messages-send.js: ".profile" DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/generics.js: "Buffer.from(value?.data || value).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString('base64')" - Network Request in lib/Utils/generics.js: "fetch('https:" - Network Request in lib/Utils/messages-media.js: "request({ hostname: parsedUrl.hostname, port: parsedUrl.port || (parsedUrl.proto..." OBFUSCATION - Dynamic Base64 Decoding in lib/Socket/newsletter.js: "Buffer.from(jid, "base64")" - Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, 'base64')" - Dynamic Base64 Decoding in lib/Utils/decode-wa-message.js: "Buffer.from(secret, 'base64')" - Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, 'base64')" - String Array Obfuscation in lib/Utils/message-composer.js: "[ 'import', 'export', 'from', 'default', 'as', 'const', 'let', 'var', 'function'..." - String Array Obfuscation in lib/Utils/messages.js: "[ 'break', 'case', 'catch', 'continue', 'debugger', 'default', 'delete', 'do', '..." - String Array Obfuscation in lib/WABinary/constants.js: "[ '1724', 'profile_picture', '1071', '1314', '1605', '407', '990', '1710', '746'..." - Decoded Base64 Content in lib/Socket/newsletter.js (x2) (+5 more) ADDITIONAL FINDINGS - Dynamic Code Execution in lib/Utils/message-composer.js: "exec(line)" PAYLOAD FILES lib/Socket/newsletter.js (+ lib/Utils/generics.js, lib/Utils/messages-media.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownxzvbaileyall (affected)

References

advisory
vendor

Browse GCVE Records

264 records in the GCVE database · Updated September 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›