@xatancchii/velycxbail@1.1.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC
OSV ID
MAL-2026-17383
Ecosystem
npm
Summary
package.json declares "libsignal": "npm:@bellaxchuu/libsignal-node@latest", aliasing the Signal-protocol crypto dependency to a package published under the unrelated @bellaxchuu scope with the mutable latest tag and no integrity check. Every npm install of @xatancchii/velycxbail resolves libsignal to whatever the current head of @bellaxchuu/libsignal-node is at install time. The aliased package is consumed by lib/Utils/crypto.js, which is reached from the main entry through the Utils layer, so arbitrary future content published to that third-party scope loads and executes as part of normal use. The scope does not match the Baileys/WhatsApp publisher chain the fork claims to derive from, so control over the code path executed on installers rests with an unrelated third party.
Source: amazon-inspector (594062e4a945ccd7c67e7a5f03085fbd2eecda766d5347b81e7012399fb1f447)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.