Malicious code in @itsmee_aizat.id/baileys2 (npm)
Description
The npm package @itsmee_aizat.id/baileys2 versions 2.0.0, 2.0.1, and 2.0.2 includes a runtime dependency on a GitHub repository (tenka-san/libsignal-node) controlled by an unrelated user. This dependency is fetched without integrity verification, allowing whoever controls that repository to execute arbitrary code on the installer's machine. The package loads this malicious code at runtime, leading to a full compromise of any computer where it is installed or running.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @itsmee_aizat.id/baileys2 npm package declares a runtime dependency on a GitHub repository (tenka-san/libsignal-node) unrelated to the package publisher and the upstream Baileys project. This dependency is resolved to the current HEAD without commit SHA, tag, or integrity checks, enabling arbitrary code execution during installation and at runtime. The malicious code is loaded via the package's lib/Signal/libsignal.js file. The package also performs read-only version probes to legitimate sources, but these do not affect the compromise. Any system with this package installed or running should be considered fully compromised.
Potential Impact
Full system compromise is possible on any computer with this package installed or running. Attackers controlling the tenka-san/libsignal-node repository can execute arbitrary code, potentially accessing all secrets and keys stored on the compromised machine. Immediate rotation of all secrets and keys from a separate, trusted machine is required. Removing the package alone does not guarantee removal of all malicious software introduced.
Mitigation Recommendations
Remove the @itsmee_aizat.id/baileys2 package immediately from all affected systems. Rotate all secrets and keys that were stored or used on compromised machines from a different, secure environment. Since the malicious code is loaded at runtime from an external GitHub repository without integrity verification, avoid installing packages with unverified external dependencies. Patch status is not confirmed; check the vendor advisory for updates. Treat affected systems as fully compromised.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-17670
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-g6w5-p954-xcfr"]
- Ecosystems
- ["npm"]
Threat ID: 6ac96e5e2cdf04f65689a8c4
Added to database: 10/09/2026, 22:44:46 UTC
Last enriched: 10/09/2026, 22:53:05 UTC
Last updated: 10/09/2026, 22:53:05 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.