Malicious NPM Package with 56K Downloads Steals WhatsApp Messages
ID: 7a2e847d-ced4-54b2-97b4-b8d8b1175177
STIX ID: report--7a2e847d-ced4-54b2-97b4-b8d8b1175177
Feed Name: cybersecurityNews.com
Threat Score
A malicious npm package called "lotusbail," presented as a fork of a trusted WhatsApp Web API library, has been stealing WhatsApp session keys, messages, contacts and media from developer systems while functioning correctly to evade detection; it used custom RSA/AES encryption, multilayer obfuscation for its exfiltration endpoint, hardcoded pairing codes to retain account access, and anti-analysis infinite loops, remaining on npm for six months with over 56,000 downloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
