Fake WhatsApp package on npm steals messages and account access
Researchers at Koi have uncovered a fake WhatsApp API package on the npm registry named lotusbail. It is a fork of the legitimate whiskeysockets/baileys package and has been downloaded more than 56,000 times. The code does what it advertises while quietly stealing WhatsApp data: messages, contacts, authentication tokens and session keys. It also contains hidden code that can link an attacker's device to the victim's WhatsApp account, giving persistent access even after the package is removed.
What this means for your organisation
WhatsApp is in practice used for customer dialogue and internal coordination in many organisations, including where it is not formally approved. If such an account is linked to an unknown device, the attacker reads along in real time, and uninstalling the package does not fix it. The content may include personal data and commercially sensitive information.
Berigo recommends
- Check whether lotusbail appears in any of your projects or build pipelines.
- Review linked devices on affected WhatsApp accounts and remove any you do not recognise.
- Introduce dependency review before new packages are adopted, not only at deployment.
- Clarify which messaging services are actually approved for business use, and for what.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch