MAL-2026-17329

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/focaleys/MAL-2026-17329.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17329
Published
2026-09-30T04:52:31Z
Modified
2026-09-30T10:32:29Z
Summary
Malicious code in focaleys (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (481093b5037c8aafc763d4543e5a6a39c2ebc7055673eb1d4f480f885593bcd2)

package.json declares the dependency 'libsignal' as 'github:rexxzyid/libsignal-node' with no tag, version, or commit SHA. On npm install, this resolves to whatever the default branch HEAD contains at that moment, with no integrity check, and any lifecycle scripts in the fetched repository execute on the installer's machine. Whoever controls the rexxzyid GitHub account controls code that runs at install time for every installer of focaleys, and the fetched code can change silently between installs without any change to focaleys itself.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020814",
            "import_time": "2026-09-30T05:19:46.269669113Z",
            "modified_time": "2026-09-30T04:52:31Z",
            "sha256": "481093b5037c8aafc763d4543e5a6a39c2ebc7055673eb1d4f480f885593bcd2",
            "source": "amazon-inspector",
            "versions": [
                "1.1.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / focaleys

Package

Affected ranges

Affected versions

1.*
1.1.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "4235344cb5abd7bf022a231b5dbf3c79a5d2aa80969910c534149ddea1908d14",
            "tlsh": "7561ca23ca8cce3318f266e9b5b40201f0b9479f1191cc5f32bd0bac4f73a561495b2a"
        }
    ],
    "package_integrity": [
        {
            "filename": "focaleys-1.1.0.tgz",
            "hashes": {
                "sha1": "4b9b22f088ba3701e2d4b03f11bbc342e577dd2d",
                "sha512_sri": "sha512-4LFvOw/ql8rii/jrS8lehCNJkC+T0OGcYoCcuv/NZ76FRxSjHJ/dqqXldbh7TK4X2PO2H+tqcFkxIXpOQMLGhw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/focaleys/MAL-2026-17329.json"