TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home General App

Malicious npm Package Compromises WhatsApp Accounts

Akinola Ajibola by Akinola Ajibola
December 23, 2025
in App, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • A fake which is assumed to be a malicious WhatsApp Web API package listed on the npm registry masquerades as a legitimate WhatsApp Web API library,...
  • Which is a highly advanced malicious npm package called lotusbail was discovered by Koi Security security researchers in December 2025.
  • It is intended to steal account information and create permanent backdoors, even though it poses as a useful WhatsApp Web API library (a fork of the...

A fake which is assumed to be a malicious WhatsApp Web API package listed on the npm registry masquerades as a legitimate WhatsApp Web API library, enabling attackers to steal messages, harvest contacts, and take over accounts.

Which is a highly advanced malicious npm package called lotusbail was discovered by Koi Security security researchers in December 2025. It is intended to steal account information and create permanent backdoors, even though it poses as a useful WhatsApp Web API library (a fork of the authentic @whiskeysockets/baileys).

The malicious software offers the genuine functionality and is a fork of the well-known WhiskeySockets Baileys project which has more than 56,000 downloads and has been available on npm under the name lotusbail for at least six months.

The malicious software was discovered by researchers from supply-chain security firm Koi Security. They revealed that it was capable of stealing WhatsApp authentication tokens and session keys, intercepting and recording all sent and received conversations, and exfiltrating contact lists, media files, and documents.

The package encapsulates the authentic WebSocket client that interacts with WhatsApp. The researchers clarify that the malware’s socket wrapper is the first thing that every message that passes through your program goes through.

“The wrapper records your credentials after you authenticate. It intercepts messages as they arrive. The messages you send are recorded.

Before being exfiltrated, the data is encrypted using a bespoke RSA implementation and several layers of obfuscation, including Unicode trickery, LZString compression, and AES encryption.

The infected software includes malware that connects the attacker’s device to the victim’s WhatsApp account via device pairing in addition to the data stealing activity.

Even once the malicious NPM package is deleted, this gives the attacker ongoing access to the account. Until the victim manually disables the connected devices from WhatsApp settings, access is still available.

Also worth reading
WhatsApp Tests A Business Folder To Tame Brand Messages WhatsApp Is Developing On-Device Scam Detection Feature For Android Users Texas Takes Action Against WhatsApp Over Encryption WhatsApp Plus Launches On iOS With Premium Features WhatsApp Tests Subscription With Largely Cosmetic Perks WhatsApp Adds Multiple Accounts For iOS

Lotusbail uses a set of 27 infinite loop traps to make debugging and analysis more difficult, according to Koi Security, which is probably why it has remained undetected for so long.

It is advised that developers who utilised the software delete it from the system and look for rogue associated devices on their WhatsApp account.

Developers should watch runtime behaviour for unexpected outbound connections or activity during authentication processes with new dependencies to evaluate their safety, according to Koi Security, as simply glancing at the source code to identify the dangerous lines is insufficient.

Take these steps if you have used lotusbail or dubious WhatsApp-related libraries:

Remove the Package: Take the package out of your project requirements right away.

Unlink Devices: On your primary mobile device, launch WhatsApp, select Settings > Linked Devices, and manually log out of any sessions that are suspicious or identified.

Audit Runtime: Keep an eye out for unusual traffic to unidentified domains in your application’s outgoing network connections.

Examine Other Packages: Naya-flore, nvlore-hsc, and @vreden/meta are more recent malicious packages that target WhatsApp developers; some of these programs contain “kill switches” that can erase local files. 

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • WhatsApp
    WhatsApp GhostPairing Scam Lets Hackers Hijack Accounts
  • claude code1
    Leaked & Exploited Claude Code Distributes…
  • WA_STRICT_SECURITY_ACCOUNT_SETTINGS_FEATURE_ANDROID
    WhatsApp Tests ‘Strict Account Settings’ for Better Security
  • Picture2
    Soon, WhatsApp Will Simplify the Process of Adding…
  • 3592
    WhatsApp Vulnerability May Have Exposed Billions of Numbers
  • WA_NEW_MULTIPLE_ACCOUNTS_FEATURE_SETTINGS_IOS
    WhatsApp Plans to Introduce Multiple Accounts Feature on iOS
  • linkedin messaging
    How Hackers Spread RAT Malware via DLL Sideloading…
  • AI_Risks-ChatGPT
    OpenAI Confirms Hack Linked to TanStack Attack
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
App Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: npmsecuritywhatsapp
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • OpenAI Gives Vetted Defenders GPT-5.6-Cyber August 11, 2026
  • Apple’s Glass iPhone Plan Is Reportedly Still Alive August 11, 2026
  • Claude Did Not Solve Riemann, But It Moved The Math August 11, 2026
  • Myspace Comeback Would Test Social Media Nostalgia August 10, 2026
  • China Review Of Palo Alto Networks Deepens Tech-Security Split August 10, 2026
  • Ethio Telecom And ZTE Push Ethiopia Closer To Nationwide 4G August 10, 2026
  • SeerBit Adds PayPal To Help African Merchants Sell Globally August 10, 2026
  • Nigeria Crypto Tax Rules Put VASPs On The Hook August 10, 2026
  • Nigeria Local Cloud Push Is Now About AI Sovereignty August 10, 2026
  • Data-Centre Bans Turn AI Compute Into Local Politics in the U.S August 10, 2026
  • Claude Agent Gym Hack Shows Everyday AI Risk August 10, 2026
  • Why China May Win The AI Race And How The US Can Still Fight August 9, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.