All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Malicious npm Package 'lotusbail' Steals WhatsApp Credentials and Messages

By

sohkamyung

5mo ago· 4 min readenNews

Summary

A malicious npm package called 'lotusbail' has been discovered stealing WhatsApp credentials and messages from developers. The package, which presents itself as a legitimate WhatsApp Web API library with over 56,000 downloads, contains sophisticated malware that intercepts messages, harvests contacts, installs persistent backdoors, and encrypts stolen data. Despite being available for 6 months, the package remains live on npm, posing a significant security threat to developers who install it without suspicion.

Key quotes

· 4 pulled
The lotusbail npm package presents itself as a WhatsApp Web API library - a fork of the legitimate @whiskeysockets/baileys package.
With over 56,000 downloads and functional code that actually works as advertised, it's the kind of dependency developers install without a second thought.
Behind that working functionality: sophisticated malware that steals your WhatsApp credentials, intercepts every message, harvests your contacts, installs a persistent backdoor, and encrypts everything before sending it.
The package has been available on npm for 6 months and is still live at the time of writing.
Snippet from the RSS feed
The lotusbail npm package presents itself as a WhatsApp Web API library - a fork of the legitimate @whiskeysockets/baileys package. With over 56,000 downloads and functional code that actually works as advertised, it's the kind of dependency developers in

You might also wanna read