Worrying WhatsApp attack can steal messages and even accounts – here’s how to stay safe from ‘poisoned’ attack


  • Malicious NPM package lotusbail hijacks WhatsApp accounts, steals tokens, messages and contacts
  • Attackers connect their device via WhatsApp pairing and continue even after the package is removed
  • The pack had 56,000+ downloads before discovery; developers are encouraged to verify sources carefully

Node Package Manager (NPM) registry users are being targeted with malware that takes over their WhatsApp accounts, stealing messages and contact lists, experts have warned.

Cybersecurity researchers Koi Security recently discovered a fork of the popular WhiskeySockets Baileys project, an open source TypeScript/JavaScript library that provides a WebSocket-based API to interact with the WhatsApp Web protocol, letting developers programmatically connect to WhatsApp as a companion device.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top