Skip to main content

Malicious code in @kxafunc/xbails (npm)

0
High
Published: 10/08/2026 (10/08/2026, 17:47:11 UTC)
Source: GCVE Database
Product: @kxafunc/xbails

Description

The npm package @kxafunc/xbails version 0.0.8 aliases its libsignal dependency to a non-standard package @bellaxchuu/libsignal-node using the mutable 'latest' dist-tag without version pinning or integrity checks. This allows whoever controls the upstream package @bellaxchuu/libsignal-node to push arbitrary code that executes within the Signal end-to-end encryption cryptographic path, potentially compromising identity keys, prekeys, and plaintext messages.

Affected software

npmghsa
@kxafunc/xbails
Affected versions
=0.0.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 22:11:58 UTC

Technical Analysis

The @kxafunc/xbails npm package version 0.0.8 uses a package.json alias to resolve its libsignal dependency to npm:@bellaxchuu/libsignal-node@latest, a non-standard publisher. This alias uses the mutable 'latest' dist-tag with no version pinning, no integrity verification, and no hash, meaning that on every install, the resolved module can change. The resolved module is loaded by critical Signal E2E encryption components (SessionCipher, SessionBuilder, ProtocolAddress, SessionRecord) that handle sensitive cryptographic material including identity keys and plaintext messages. Control over the upstream package name @bellaxchuu/libsignal-node allows an attacker to inject arbitrary code into every installation, executing within the encryption/decryption path and compromising the security guarantees of Signal's cryptography. This vulnerability arises from an off-registry trust relationship embedded in the manifest itself, independent of the current contents of the alias target.

Potential Impact

An attacker controlling the upstream package @bellaxchuu/libsignal-node can execute arbitrary code within the Signal end-to-end encryption process of @kxafunc/xbails version 0.0.8. This can lead to compromise of identity keys, prekeys, and plaintext messages, effectively breaking the confidentiality and integrity of encrypted communications relying on this package.

Mitigation Recommendations

No official patch or remediation is indicated in the provided data. Users should avoid using @kxafunc/xbails version 0.0.8 due to its reliance on a mutable alias to an untrusted upstream package. Until a fix is available, do not install or update this package. Monitor the vendor advisory or package repository for updates that remove the mutable alias and implement version pinning and integrity checks.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-17701
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6ac80fb92cdf04f65639c2b0

Added to database: 10/08/2026, 21:48:41 UTC

Last enriched: 10/08/2026, 22:11:58 UTC

Last updated: 10/08/2026, 22:11:58 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses