1 link tagged with all of: security + malware + npm + whatsapp + supply-chain
Links
The lotusbail npm package masquerades as a legitimate WhatsApp API library but contains sophisticated malware that steals user credentials, messages, and contacts. It captures data by intercepting communications and uses custom encryption to evade detection. Even after uninstalling the package, attackers retain access to compromised accounts.
malware ✓
npm ✓
whatsapp ✓
security ✓
supply-chain ✓