Malicious code in @kxafunc/xbails (npm)
Description
The npm package @kxafunc/xbails version 0.0.8 aliases its libsignal dependency to a non-standard package @bellaxchuu/libsignal-node using the mutable 'latest' dist-tag without version pinning or integrity checks. This allows whoever controls the upstream package @bellaxchuu/libsignal-node to push arbitrary code that executes within the Signal end-to-end encryption cryptographic path, potentially compromising identity keys, prekeys, and plaintext messages.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @kxafunc/xbails npm package version 0.0.8 uses a package.json alias to resolve its libsignal dependency to npm:@bellaxchuu/libsignal-node@latest, a non-standard publisher. This alias uses the mutable 'latest' dist-tag with no version pinning, no integrity verification, and no hash, meaning that on every install, the resolved module can change. The resolved module is loaded by critical Signal E2E encryption components (SessionCipher, SessionBuilder, ProtocolAddress, SessionRecord) that handle sensitive cryptographic material including identity keys and plaintext messages. Control over the upstream package name @bellaxchuu/libsignal-node allows an attacker to inject arbitrary code into every installation, executing within the encryption/decryption path and compromising the security guarantees of Signal's cryptography. This vulnerability arises from an off-registry trust relationship embedded in the manifest itself, independent of the current contents of the alias target.
Potential Impact
An attacker controlling the upstream package @bellaxchuu/libsignal-node can execute arbitrary code within the Signal end-to-end encryption process of @kxafunc/xbails version 0.0.8. This can lead to compromise of identity keys, prekeys, and plaintext messages, effectively breaking the confidentiality and integrity of encrypted communications relying on this package.
Mitigation Recommendations
No official patch or remediation is indicated in the provided data. Users should avoid using @kxafunc/xbails version 0.0.8 due to its reliance on a mutable alias to an untrusted upstream package. Until a fix is available, do not install or update this package. Monitor the vendor advisory or package repository for updates that remove the mutable alias and implement version pinning and integrity checks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-17701
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6ac80fb92cdf04f65639c2b0
Added to database: 10/08/2026, 21:48:41 UTC
Last enriched: 10/08/2026, 22:11:58 UTC
Last updated: 10/08/2026, 22:11:58 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.