Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-17329 confirms this npm version as malicious. package.json declares the dependency 'libsignal' as 'github:rexxzyid/libsignal-node' with no tag, version, or commit SHA. On npm install, this resolves to whatever the default branch HEAD contains at that moment, with no integrity check, and any lifecycle scripts in the fetched repository execute on the installer's machine...
This report applies to focaleys@1.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.