CRITICAL npm Malware

Malicious code in xzvbailsx (npm)

MAL-2026-16279

Published · Modified

Dependency scanning

Check whether xzvbailsx is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (ac9176da252791a96b93c24e702c2245fb96d9655cdf9f31d61e9bc3e0c21528)

package.json declares the dependency libsignal with source github:tenka-san/libsignal-node, an unpinned GitHub ref with no commit SHA, tag, or integrity hash. On npm install, npm fetches whatever HEAD of that repository currently points at and executes any lifecycle scripts (preinstall/install/postinstall) it contains on the installer's machine. The referenced GitHub account is a personal repository unrelated to the WhiskeySockets/Baileys upstream that this package forks. Provenance is further obscured by an identity mismatch: the package is published as xzvbailsx but README/examples describe it as @XzV-RxVz/xbails, and the repository field points to Telegram handles (t.me/JustRxVz, t.me/XzV_ExpzC) rather than a source repository.

Ready to move

Start Securing

Free, no credit card | First findings in minutes