@bellaxchuu/crystalred@0.1.2
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC
OSV ID
MAL-2026-17343
Ecosystem
npm
Summary
package.json declares the libsignal dependency as github:Bellaxata/libsignal-node with no commit SHA, tag, or semver pin. On npm install, this resolves to the current HEAD of that GitHub repository and executes whatever lifecycle scripts and code that repo ships at fetch time. Because the source is off-registry and integrity-unchecked, the executed code can change at any moment without a version bump of @bellaxchuu/crystalred, giving the account controlling Bellaxata/libsignal-node arbitrary code execution on any machine installing this package.
Source: amazon-inspector (db80e6c4fd1d63c2fd93dd289e6a09d2e17d90e1472a6e172b453a213d63ee01)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.