Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

NPM Package With 56,000 Downloads Steals WhatsApp Credentials, Data

The package provides legitimate functionality to evade detection, while stealing users’ data and deploying a backdoor.

Vulnerability

A malicious NPM package that functions as a WhatsApp Web API library has been caught stealing users’ credentials and data, Koi Security warns.

The package, ‘Lotusbail’, a fork of the ‘Baileys’ library, has been available in the NPM repository for six months and has gathered over 56,000 downloads to date.

According to Koi, Lotusbail supports sending and receiving WhatsApp messages. It wraps the legitimate WebSocket client and every message goes through the wrapper first.

This means that the wrapper captures users’ credentials, as well as all incoming and outgoing messages, and delivers all the information to the malware operator.

“All your WhatsApp authentication tokens, every message sent or received, complete contact lists, media files – everything that passes through the API gets duplicated and prepared for exfiltration,” Koi says.

The package encrypts all the collected information using a custom RSA implementation before transmission, to evade detection.

Advertisement. Scroll to continue reading.

Additionally, the malware was observed hijacking WhatsApp’s device pairing process to add the attacker’s own device and gain backdoor access to a victim’s account.

“When you use this library to authenticate, you’re not just linking your application – you’re also linking the threat actor’s device. They have complete, persistent access to your WhatsApp account, and you have no idea they’re there,” Koi notes.

Uninstalling the malicious package, Koi explains, is not enough to remove the attackers’ access. Victims need to manually unlink all devices from WhatsApp’s settings.

The Lotusbail NPM package, the cybersecurity firm notes, is part of a sophisticated supply chain attack that also includes dozens of checks for debuggers, sandboxes, and other analysis tools, to evade traditional detection.

Related: 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack

Related: Amazon Detects 150,000 NPM Packages in Worm-Powered Campaign

Related: Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm

Related: Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.