Tea Token Farming Campaign appears to be a threat operation distributing a poisoned WhatsApp API package that steals WhatsApp messages and user accounts.
Tea Token Farming Campaign appears to be a threat operation distributing a poisoned WhatsApp API package that steals WhatsApp messages and user accounts. The campaign leverages a compromised WhatsApp API package to exfiltrate messages and credential data, highlighting a significant risk to both personal and organizational WhatsApp communications.
A malicious npm package named lotusbail, masquerading as a WhatsApp Web API library, has been found to steal WhatsApp messages, credentials, and contacts. This package has been available for at least six months and has…