logo

Popular NPM Package lotusbail Exposed as Trojan Stealing WhatsApp Chats

ID: 7beb9d16-08a2-5ee5-bef5-182733772e11

STIX ID: report--7beb9d16-08a2-5ee5-bef5-182733772e11

Feed Name: HackRead

Threat Score
80/100

Date Published: 2025-12-26

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Koi Security discovered a malicious npm package, `lotusbail`, that impersonated a trusted WhatsApp library and silently wrapped the WebSocket communication channel to copy and exfiltrate full chat history, contacts, media, and authentication tokens. The package—downloaded over 56,000 times—also hijacks WhatsApp pairing to maintain persistent attacker access and includes custom RSA encryption and anti-analysis traps to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.