Malicious npm Package 'lotusbail' Steals WhatsApp Credentials and Messages
By
sohkamyung
Properly proved. Has structure, has flavour, has a point.
Summary
A malicious npm package called 'lotusbail' has been discovered stealing WhatsApp credentials and messages from developers. The package, which presents itself as a legitimate WhatsApp Web API library with over 56,000 downloads, contains sophisticated malware that intercepts messages, harvests contacts, installs persistent backdoors, and encrypts stolen data. Despite being available for 6 months, the package remains live on npm, posing a significant security threat to developers who install it without suspicion.
Key quotes
· 4 pulledThe lotusbail npm package presents itself as a WhatsApp Web API library - a fork of the legitimate @whiskeysockets/baileys package.
With over 56,000 downloads and functional code that actually works as advertised, it's the kind of dependency developers install without a second thought.
Behind that working functionality: sophisticated malware that steals your WhatsApp credentials, intercepts every message, harvests your contacts, installs a persistent backdoor, and encrypts everything before sending it.
The package has been available on npm for 6 months and is still live at the time of writing.
You might also wanna read
AI-Generated npm Package Leaks Its Own GitHub Token, Exposing Malware Operator
A malicious npm package named mouse5212-super-formatter, identified by OX Security, was caught leaking its own hardcoded GitHub token. This
176 malicious npm packages used dependency confusion to target internal dependencies and steal credentials
Sonatype researchers uncovered a campaign involving 176 malicious npm packages using a dependency confusion attack strategy. Attackers publi
Microsoft detects 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries
A threat actor using the alias vpmdhaj published 14 malicious npm packages within four hours, impersonating legitimate OpenSearch, Elasticse
North Korean Chollima Group Targets PHP Developers via Malicious Packagist Package
A malicious obfuscated JavaScript payload was discovered appended to tailwind.js in the Packagist development version dev-drewroberts/featur
npm malware targeting Claude users leaks own GitHub token, reaches 676 downloads
An npm package called "mouse5212-super-formatter" targeting Claude users acted as information-stealing malware, reaching 676 downloads befor
