Malware, DevOps, Supply chain, Application security

Malicious npm package ‘lotusbail’ steals WhatsApp data, hijacks accounts

(Credit: Araki Illustrations – stock.adobe.com)

As detailed in The Hacker News, cybersecurity researchers have uncovered a sophisticated malicious package named "lotusbail" on the npm repository. This package masquerades as a functional WhatsApp API but secretly possesses the capability to intercept all messages and link an attacker's device to a victim's WhatsApp account.

The "lotusbail" package, downloaded over 56,000 times since May 2025, operates by wrapping the WebSocket client used for WhatsApp API interactions. This allows it to capture authentication tokens, session keys, message history, contact lists, and media files. A particularly concerning feature is its ability to hijack the device linking process using a hard-coded pairing code, granting the attacker persistent access to the victim's WhatsApp account even after the package is uninstalled. The malware also includes anti-debugging capabilities to evade detection. This disclosure follows reports of 14 malicious NuGet packages targeting the cryptocurrency ecosystem by impersonating legitimate libraries to redirect funds or steal private keys.

The increasing sophistication of supply chain attacks, like the 'lotusbail' incident, highlights significant gaps in traditional security measures. Static analysis and download reputation systems are insufficient to detect such threats, which hide malicious code within seemingly legitimate functionalities. This trend underscores the urgent need for enhanced security practices in software development and a greater focus on verifying the integrity of third-party libraries to prevent widespread compromise and protect sensitive user data.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds