libas-signalnpm
libas-signal is a confirmed malicious npm package (MAL-2026-14291) that executes malicious code on install (malicious version 1.0.0). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in libas-signal (npm)
What this malware does
On require() of libas-signal, index.js schedules install.js which locates the installer's @whiskeysockets/baileys package on disk and overwrites lib/Socket/newsletter.js with a modified copy. The injected code, when the installer later runs their Baileys-based WhatsApp bot, silently issues a FOLLOW newsletterWMexQuery against hardcoded channel 120363407277177688@newsletter using the installer's authenticated WhatsApp session. The patch persists on disk after libas-signal exits and continues to run inside the unrelated dependency. The package's advertised identity (Signal Protocol / Whisper Systems crypto library, with a src/ tree copying Signal Protocol code) is unrelated to this behavior and functions as cover for the dependency-tampering payload.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Malicious packageFind it
Search your lockfiles and build artifacts for libas-signal (version 1.0.0).
If you installed it — respond
Remove libas-signal from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.
Did it already run?
If libas-signal was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks libas-signal-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.