Poisoned WhatsApp API Package Steals Messages and Accounts
The lotusbail package, downloaded over 56,000 times, steals WhatsApp tokens and messages, granting attackers persistent access via device pairing until manually revoked.
9 Articles
9 Articles
The latest case of malware on WhatsApp shows that the danger no longer comes only through strange links or dubious attachments. Sometimes, the problem is much further back, at the very origin of some apps we use daily. Recent research has uncovered how a seemingly legitimate add-on has been able to steal private messages without users or developers noticing for months. A malware that does not attack the user, but at the origin of apps The warnin…
Developers Hit as Fake WhatsApp API Package Emerges on npm
Security researchers discovered a fake WhatsApp API package on npm that steals developer credentials, raising fresh alarms about the growing risks facing the open source software supply chain. The malicious package impersonated a legitimate WhatsApp API library and actively harvested sensitive information from unsuspecting developers who installed it, highlighting how threat actors continue to exploit […] The post Developers Hit as Fake WhatsApp…
WhatsApp API worked exactly as promised, and stole everything
Security researchers have uncovered a malicious npm package that poses as a legitimate WhatsApp Web API library while quietly stealing messages, credentials, and contact data from developer environments. The package, identified as “lotusbail,” operates as a trojanized wrapper around a genuine WhatsApp client library and had accumulated more than 50k downloads by the time it was flagged by Koi Security. “With over 56000 downloads and functional c…
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








