Popular NPM Package lotusbail Exposed as Trojan Stealing WhatsApp Chats
ID: 7beb9d16-08a2-5ee5-bef5-182733772e11
STIX ID: report--7beb9d16-08a2-5ee5-bef5-182733772e11
Feed Name: HackRead
Threat Score
Koi Security discovered a malicious npm package, `lotusbail`, that impersonated a trusted WhatsApp library and silently wrapped the WebSocket communication channel to copy and exfiltrate full chat history, contacts, media, and authentication tokens. The package—downloaded over 56,000 times—also hijacks WhatsApp pairing to maintain persistent attacker access and includes custom RSA encryption and anti-analysis traps to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
