Feeds.Feedburner
Malicious NPM Package Steals WhatsApp Data from 56,000 Users
First seen 23 Dec 2025, 12:00 UTC
•


•80% similarity
•29.2
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A malicious NPM package named 'lotusbail' has been downloaded over 56,000 times and is stealing WhatsApp messages and user data from developers worldwide. Disguised as a legitimate WhatsApp Web API library, it operates as a fork of the trusted '@whiskeysockets/baileys' package while running malware in the background.
ThreatCluster AI
How this analysis works