As detailed in The Hacker News, cybersecurity researchers have uncovered a sophisticated malicious package named "lotusbail" on the npm repository. This package masquerades as a functional WhatsApp API but secretly possesses the capability to intercept all messages and link an attacker's device to a victim's WhatsApp account.The "lotusbail" package, downloaded over 56,000 times since May 2025, operates by wrapping the WebSocket client used for WhatsApp API interactions. This allows it to capture authentication tokens, session keys, message history, contact lists, and media files. A particularly concerning feature is its ability to hijack the device linking process using a hard-coded pairing code, granting the attacker persistent access to the victim's WhatsApp account even after the package is uninstalled. The malware also includes anti-debugging capabilities to evade detection. This disclosure follows reports of 14 malicious NuGet packages targeting the cryptocurrency ecosystem by impersonating legitimate libraries to redirect funds or steal private keys.The increasing sophistication of supply chain attacks, like the 'lotusbail' incident, highlights significant gaps in traditional security measures. Static analysis and download reputation systems are insufficient to detect such threats, which hide malicious code within seemingly legitimate functionalities. This trend underscores the urgent need for enhanced security practices in software development and a greater focus on verifying the integrity of third-party libraries to prevent widespread compromise and protect sensitive user data.Source: The Hacker News
Malware, DevOps, Supply chain, Application security

Malicious npm package ‘lotusbail’ steals WhatsApp data, hijacks accounts
(Credit: Araki Illustrations – stock.adobe.com)

Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
