Malicious code in xzvbailsx (npm)
MAL-2026-16279
Published · Modified
Dependency scanning
Check whether xzvbailsx is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (ac9176da252791a96b93c24e702c2245fb96d9655cdf9f31d61e9bc3e0c21528)
package.json declares the dependency libsignal with source github:tenka-san/libsignal-node, an unpinned GitHub ref with no commit SHA, tag, or integrity hash. On npm install, npm fetches whatever HEAD of that repository currently points at and executes any lifecycle scripts (preinstall/install/postinstall) it contains on the installer's machine. The referenced GitHub account is a personal repository unrelated to the WhiskeySockets/Baileys upstream that this package forks. Provenance is further obscured by an identity mismatch: the package is published as xzvbailsx but README/examples describe it as @XzV-RxVz/xbails, and the repository field points to Telegram handles (t.me/JustRxVz, t.me/XzV_ExpzC) rather than a source repository.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes