{"_id":"@akaanakbaik/libsignal","name":"@akaanakbaik/libsignal","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@akaanakbaik/libsignal","version":"1.0.0","description":"Modernized fork of WhiskeySockets/libsignal-node for @kelvdra/baileys — zero-breaking-change audit and maintenance update","homepage":"https://github.com/akaanakbaik/libsignal#readme","repository":{"type":"git","url":"git+https://github.com/akaanakbaik/libsignal.git"},"bugs":{"url":"https://github.com/akaanakbaik/libsignal/issues"},"main":"index.js","types":"index.d.ts","keywords":["signal","whispersystems","crypto","whatsapp","baileys"],"license":"GPL-3.0","engines":{"node":">=16.0.0"},"dependencies":{"curve25519-js":"^0.0.4","protobufjs":"^7.5.5"},"devDependencies":{"eslint":"^8.57.1"},"sideEffects":false,"scripts":{"lint":"eslint src/ --ext .js","test":"node --test test/*.test.js","test:log":"node --test --test-reporter=spec test/*.test.js","test:coverage":"node --experimental-test-coverage --test test/*.test.js"},"publishConfig":{"access":"public"},"_id":"@akaanakbaik/libsignal@1.0.0","gitHead":"6828cc398f122c764dcf99892e10c20c415f9641","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-jxEqc3PXBq7c9hcdDIZukXXAF1bVF/W482dTtVKVIsxT5wPAFgfA+RD1qaKig6TuKTZUlLpvdmao2rB4cm3wkw==","shasum":"6e8d09cf385692c7971f3dd53c274150fbecbbe9","tarball":"https://registry.npmjs.org/@akaanakbaik/libsignal/-/libsignal-1.0.0.tgz","fileCount":22,"unpackedSize":137881,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGnPL9nI+kvnDUMItABwyq67cAUvJ7Zbd0PLgLbjO4ZkAiEA5U+RqbiHSMYIihLiNqzgNMp+kLXpog+5hkD7+Iz1G24="}]},"_npmUser":{"name":"akaanakbaik","email":"khaliqarrasyidabdul@gmail.com"},"directories":{},"maintainers":[{"name":"akaanakbaik","email":"khaliqarrasyidabdul@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/libsignal_1.0.0_1783339676970_0.26578726445793466"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-06T12:07:56.818Z","1.0.0":"2026-07-06T12:07:57.137Z","modified":"2026-07-06T12:07:57.343Z"},"maintainers":[{"name":"akaanakbaik","email":"khaliqarrasyidabdul@gmail.com"}],"description":"Modernized fork of WhiskeySockets/libsignal-node for @kelvdra/baileys — zero-breaking-change audit and maintenance update","homepage":"https://github.com/akaanakbaik/libsignal#readme","keywords":["signal","whispersystems","crypto","whatsapp","baileys"],"repository":{"type":"git","url":"git+https://github.com/akaanakbaik/libsignal.git"},"bugs":{"url":"https://github.com/akaanakbaik/libsignal/issues"},"license":"GPL-3.0","readme":"# @akaanakbaik/libsignal\n\n**Modernized, security-hardened fork of the Signal Protocol for Node.js**\n\n[![npm version](https://img.shields.io/npm/v/@akaanakbaik/libsignal.svg?style=flat-square)](https://www.npmjs.com/package/@akaanakbaik/libsignal)\n[![npm downloads](https://img.shields.io/npm/dm/@akaanakbaik/libsignal.svg?style=flat-square)](https://www.npmjs.com/package/@akaanakbaik/libsignal)\n[![GitHub last commit](https://img.shields.io/github/last-commit/akaanakbaik/libsignal?style=flat-square)](https://github.com/akaanakbaik/libsignal/commits/master)\n[![License: GPL v3](https://img.shields.io/badge/License-GPLv3-blue.svg?style=flat-square)](LICENSE)\n[![Node.js CI](https://img.shields.io/github/actions/workflow/status/akaanakbaik/libsignal/ci.yml?branch=master&style=flat-square)](https://github.com/akaanakbaik/libsignal/actions?query=workflow%3ACI)\n[![CodeQL](https://img.shields.io/github/actions/workflow/status/akaanakbaik/libsignal/ci.yml?branch=master&style=flat-square&label=CodeQL)](https://github.com/akaanakbaik/libsignal/security/code-scanning)\n[![Node Version](https://img.shields.io/badge/node-%3E%3D16-brightgreen?style=flat-square)](package.json)\n\n---\n\n## Overview\n\n`@akaanakbaik/libsignal` is a pure JavaScript implementation of the **Signal Protocol** — the cryptographic protocol that powers WhatsApp, Signal Messenger, and other end-to-end encrypted messaging applications.\n\nThis is a **modernized fork** of [WhiskeySockets/libsignal-node](https://github.com/WhiskeySockets/libsignal-node). It provides:\n\n- **Zero Breaking Changes** — 100% API compatible with the original\n- **Security Hardened** — All sensitive data leakage via console logging removed\n- **Enterprise Quality** — Comprehensive testing, CI/CD, and documentation\n- **Long-Term Maintainable** — Clean codebase with full documentation\n\n## Features\n\n- 🔐 **Signal Protocol v3** — X3DH key agreement + Double Ratchet algorithm\n- 🔑 **X25519 Key Agreement** — Curve25519 ECDH for forward secrecy\n- 📝 **Ed25519 Signatures** — Signed pre-keys for identity verification\n- 🗄️ **AES-256-CBC Encryption** — Symmetric message encryption\n- 🔄 **Session Management** — Multi-session support with cleanup\n- 📦 **Pure JavaScript** — No native compilation required\n- 🎯 **Baileys Compatible** — Drop-in replacement for `@kelvdra/baileys`\n\n## Why This Fork?\n\nThe original `WhiskeySockets/libsignal-node` package:\n\n1. **Leaks sensitive data**: Console.log/info/warn calls expose private keys, session records, and registration IDs to stdout/stderr\n2. **Lacks testing**: No unit tests, no regression tests, no CI/CD\n3. **Limited documentation**: No API reference, architecture docs, or security guide\n4. **No publish config**: Git URL dependencies cause installation issues\n\nThis fork addresses all these issues while maintaining **100% backward compatibility**.\n\n## Installation\n\n```bash\nnpm install @akaanakbaik/libsignal\n```\n\n## Usage\n\n### Basic Usage\n\n```javascript\nconst libsignal = require('@akaanakbaik/libsignal');\n\n// OR (ESM / TypeScript)\nimport * as libsignal from '@akaanakbaik/libsignal';\n```\n\n### With Baileys\n\n```javascript\n// Works with @kelvdra/baileys and WhiskeySockets/Baileys\nconst libsignal = require('@akaanakbaik/libsignal');\n\n// Or configure your Baileys instance to use this package\n```\n\n### Key Generation\n\n```javascript\nconst { keyhelper, curve, ProtocolAddress } = require('@akaanakbaik/libsignal');\n\n// Generate identity key pair\nconst identityKeyPair = keyhelper.generateIdentityKeyPair();\n\n// Generate registration ID\nconst registrationId = keyhelper.generateRegistrationId();\n\n// Generate signed pre-key\nconst signedPreKey = keyhelper.generateSignedPreKey(identityKeyPair, 1);\n\n// Generate one-time pre-key\nconst preKey = keyhelper.generatePreKey(1);\n```\n\n### Session Establishment\n\n```javascript\nconst { SessionBuilder, SessionCipher, ProtocolAddress } = require('@akaanakbaik/libsignal');\n\n// Create address for remote device\nconst remoteAddr = new ProtocolAddress('user@example.com', 1);\n\n// Storage interface (implement by your app)\nconst storage = {\n    loadSession: async (id) => { /* ... */ },\n    storeSession: async (id, session) => { /* ... */ },\n    isTrustedIdentity: (identifier, identityKey) => { /* ... */ },\n    loadPreKey: async (id) => { /* ... */ },\n    removePreKey: (id) => { /* ... */ },\n    loadSignedPreKey: () => { /* ... */ },\n    getOurRegistrationId: () => { /* ... */ },\n    getOurIdentity: () => { /* ... */ }\n};\n\n// Initiate session\nconst builder = new SessionBuilder(storage, remoteAddr);\nawait builder.initOutgoing({\n    registrationId: 12345,\n    identityKey: someIdentityKey,\n    signedPreKey: { keyId: 1, publicKey: pubKey, signature: sig },\n    preKey: { keyId: 1, publicKey: pubKey }\n});\n```\n\n### Message Encryption/Decryption\n\n```javascript\nconst cipher = new SessionCipher(storage, remoteAddr);\n\n// Encrypt\nconst { type, body, registrationId } = await cipher.encrypt(\n    Buffer.from('Hello, World!')\n);\n\n// Decrypt (standard message)\nconst plaintext = await cipher.decryptWhisperMessage(body);\n\n// Decrypt (pre-key message)\nconst plaintext = await cipher.decryptPreKeyWhisperMessage(preKeyMessage);\n```\n\n## API\n\n### Exports\n\n| Export | Description |\n|--------|-------------|\n| `crypto` | AES-256-CBC, HMAC-SHA256, SHA-512, HKDF |\n| `curve` | X25519 key agreement, Ed25519 signatures |\n| `keyhelper` | Key generation (identity, pre-keys, signed pre-keys) |\n| `ProtocolAddress` | Device address representation |\n| `SessionBuilder` | Session establishment (X3DH) |\n| `SessionCipher` | Message encryption/decryption (Double Ratchet) |\n| `SessionRecord` | Session state persistence |\n| `SignalError` | Base error class |\n| `UntrustedIdentityKeyError` | Untrusted identity error |\n| `SessionError` | Session error |\n| `MessageCounterError` | Message counter error |\n| `PreKeyError` | Pre-key error |\n\nFor full API documentation, see [API_REFERENCE.md](API_REFERENCE.md).\n\n## Migration Guide\n\n### From libsignal (npm) or WhiskeySockets/libsignal-node\n\n1. Update your `package.json`:\n```json\n{\n  \"dependencies\": {\n    \"libsignal\": \"npm:@akaanakbaik/libsignal@^1.0.0\"\n  }\n}\n```\n\n2. Or replace the package name:\n```json\n{\n  \"dependencies\": {\n    \"@akaanakbaik/libsignal\": \"^1.0.0\"\n  }\n}\n```\n\n3. Update your imports:\n```javascript\n// Old\nconst libsignal = require('libsignal');\n\n// New\nconst libsignal = require('@akaanakbaik/libsignal');\n```\n\n**No other code changes required.** All APIs, classes, methods, parameters, return values, and error types are identical.\n\n## Compatibility Matrix\n\n### Node.js Versions\n\n| Version | Supported |\n|---------|-----------|\n| 16.x | ✅ |\n| 18.x | ✅ |\n| 20.x | ✅ |\n| 22.x | ✅ |\n| 24.x | ⏳ (planned) |\n\n### Baileys Versions\n\n| Version | Compatible |\n|---------|------------|\n| WhiskeySockets/Baileys 6.x | ✅ |\n| @kelvdra/baileys 1.x | ✅ |\n\n### Platforms\n\n| Platform | Architecture | Status |\n|----------|-------------|--------|\n| Ubuntu 20.04+ | x64, arm64 | ✅ |\n| Debian 11+ | x64, arm64 | ✅ |\n| macOS 12+ | x64, arm64 | ✅ |\n| Windows Server 2019+ | x64 | ✅ |\n| Windows 10+ | x64 | ✅ |\n\n## Security\n\n### What We Fixed\n\n- **Removed all console.log/info/warn/error** calls that leaked:\n  - Private keys\n  - Ephemeral keys\n  - Root keys\n  - Pending pre-keys\n  - Registration IDs\n  - Session records\n  - Error stack traces\n\n### What We Guarantee\n\n- **Zero sensitive data** printed to stdout/stderr\n- **Zero cryptographic changes** — protocol behavior is identical\n- **Zero API changes** — 100% backward compatible\n- **Regression tests** ensure no console logging is reintroduced\n\nSee [SECURITY.md](SECURITY.md) for vulnerability reporting and [SECURITY_ARCHITECTURE.md](SECURITY_ARCHITECTURE.md) for detailed security analysis.\n\n## Performance\n\nBenchmarks available in [test/benchmark.test.js](test/benchmark.test.js).\n\nRun benchmarks:\n```bash\nnode --test test/benchmark.test.js\n```\n\n## Development\n\n```bash\n# Clone\ngit clone https://github.com/akaanakbaik/libsignal.git\ncd libsignal\n\n# Install\nnpm install\n\n# Test\nnpm test\n\n# Lint\nnpx eslint src/\nnpx prettier --check \"src/**/*.js\" \"index.js\"\n```\n\nSee [DEVELOPMENT_GUIDE.md](DEVELOPMENT_GUIDE.md) for full development setup.\n\n## Documentation Index\n\n| Document | Description |\n|----------|-------------|\n| [README.md](README.md) | This file |\n| [API_REFERENCE.md](API_REFERENCE.md) | Complete API documentation |\n| [ARCHITECTURE.md](ARCHITECTURE.md) | Architecture overview |\n| [DESIGN.md](DESIGN.md) | Design decisions and rationale |\n| [INTERNALS.md](INTERNALS.md) | Internal implementation details |\n| [SECURITY_ARCHITECTURE.md](SECURITY_ARCHITECTURE.md) | Security analysis |\n| [SECURITY.md](SECURITY.md) | Security policy and vulnerability reporting |\n| [CONTRIBUTING.md](CONTRIBUTING.md) | Contributing guidelines |\n| [DEVELOPMENT_GUIDE.md](DEVELOPMENT_GUIDE.md) | Development setup |\n| [TESTING_GUIDE.md](TESTING_GUIDE.md) | Testing guide |\n| [RELEASE_GUIDE.md](RELEASE_GUIDE.md) | Release process |\n| [CHANGELOG.md](CHANGELOG.md) | Version history |\n| [ROADMAP.md](ROADMAP.md) | Future plans |\n| [AGENTS.md](AGENTS.md) | AI/Agent guide |\n| [LAPORAN.md](LAPORAN.md) | Master audit report |\n\n## FAQ\n\n### Why does this package exist?\n\nThe original `WhiskeySockets/libsignal-node` had several issues: sensitive data leaked through console logs, no testing, no CI/CD, and limited documentation. This fork addresses all these issues while maintaining 100% backward compatibility.\n\n### Is this compatible with Baileys?\n\nYes. This is designed as a drop-in replacement for the `libsignal` dependency in `@kelvdra/baileys`. No code changes needed.\n\n### Does this change the Signal Protocol?\n\nNo. Zero changes to cryptographic algorithms, session format, message format, serialization, or any protocol behavior.\n\n### Can I use this with the official Signal app?\n\nNo. This is a Node.js implementation for server-side use. The official Signal app uses `@signalapp/libsignal-client`.\n\n### Why not use @signalapp/libsignal-client?\n\nThe official library uses native Rust bindings and has a different API. Switching would require significant changes to Baileys.\n\n### Will this package receive updates?\n\nYes. We maintain this package for the `@kelvdra/baileys` project and welcome community contributions.\n\n## License\n\n[GPL-3.0](LICENSE) — This is a fork of [WhiskeySockets/libsignal-node](https://github.com/WhiskeySockets/libsignal-node), which is licensed under GPL-3.0.\n\n## Credits\n\n- **WhiskeySockets** — Original [libsignal-node](https://github.com/WhiskeySockets/libsignal-node) implementation\n- **Adiwajshing** — Original [Baileys](https://github.com/adiwajshing/Baileys) project\n- **Signal Foundation** — The [Signal Protocol](https://signal.org/docs/) specification\n\n## Support\n\n- [GitHub Issues](https://github.com/akaanakbaik/libsignal/issues)\n- [Security Issues](SECURITY.md)\n- [Documentation](https://github.com/akaanakbaik/libsignal#readme)\n","readmeFilename":"README.md","_rev":"1-59ddf1af46efd8c7aa942064ef78681b"}