logo

Malicious npm package steals WhatsApp accounts and messages

ID: 20d56c1d-2127-5433-83f9-bf714e53ed83

STIX ID: report--20d56c1d-2127-5433-83f9-bf714e53ed83

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious npm package called 'lotusbail', a fork of the Baileys WhatsApp Web client, was available on npm for at least six months and amassed over 56,000 downloads; it wraps the WebSocket client to capture WhatsApp authentication tokens, messages, contacts, and media, exfiltrates data (using multiple layers of obfuscation and encryption), and can persistently link an attacker to a victim's WhatsApp account via device pairing, so developers are advised to remove the package and check for linked devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.