Worrying WhatsApp attack can steal messages and even accounts – here’s how to stay safe from a ‘poisoned’ attack



  • Malicious NPM lotusbail package hijacks WhatsApp accounts and steals tokens, messages and contacts
  • Attackers link your device via WhatsApp pairing and persist even after package removal.
  • The package had more than 56,000 downloads before it was discovered; Developers are urged to check sources carefully.

Node Package Manager (NPM) registry users are being attacked by malware that takes over their WhatsApp accounts, steals messages and contact lists, experts have warned.

Cybersecurity researchers Koi Security recently discovered a fork of the popular WhiskeySockets Baileys project, an open source TypeScript/JavaScript library that provides a WebSocket-based API to interact with the WhatsApp web protocol, allowing developers to programmatically connect to WhatsApp as an add-on device.



Leave a Comment

Your email address will not be published. Required fields are marked *