logo

Malicious NPM Package with 56K Downloads Steals WhatsApp Messages

ID: 7a2e847d-ced4-54b2-97b4-b8d8b1175177

STIX ID: report--7a2e847d-ced4-54b2-97b4-b8d8b1175177

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious npm package called "lotusbail," presented as a fork of a trusted WhatsApp Web API library, has been stealing WhatsApp session keys, messages, contacts and media from developer systems while functioning correctly to evade detection; it used custom RSA/AES encryption, multilayer obfuscation for its exfiltration endpoint, hardcoded pairing codes to retain account access, and anti-analysis infinite loops, remaining on npm for six months with over 56,000 downloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.