Malicious NPM Package Steals WhatsApp Data from 56,000 Users

Malicious NPM Package Steals WhatsApp Data from 56,000 Users

First seen 23 Dec 2025, 12:00 UTC CybersecuritynewsGbhackersFeeds.FeedburnerSecurityaffairs.Co 80% similarity 29.2

Article Content

Browse articles
ThreatCluster

A malicious NPM package named 'lotusbail' has been downloaded over 56,000 times and is stealing WhatsApp messages and user data from developers worldwide. Disguised as a legitimate WhatsApp Web API library, it operates as a fork of the trusted '@whiskeysockets/baileys' package while running malware in the background.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story