logo

Poisoned WhatsApp API package steals messages and accounts

ID: 005b0a90-b513-5126-9055-c75f5033cdc2

STIX ID: report--005b0a90-b513-5126-9055-c75f5033cdc2

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2025-12-22

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A malicious npm package called "lotusbail", a fork of the legitimate Baileys WhatsApp library, has been available for six months with over 56,000 downloads; it functions as a working WhatsApp API while intercepting and exfiltrating authentication tokens, messages, contacts, and media, uses multiple obfuscation and encryption layers, and can backdoor victims' WhatsApp accounts via device pairing, demonstrating a significant supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.