Skip to content
Threat Intelby Edward Kiledjian
SearchRSS
Archive About Contact Privacy

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

A malicious npm package named lotusbail has been discovered that functions as a WhatsApp API but secretly steals messages, contacts, and login tokens. This package, downloaded over 56,000 times, hijacks the device linking process to maintain persistent access to a victim’s WhatsApp account, even after being uninstalled.

Source: thehackernews.com

Curated Dec 22, 2025 · 2:09 PMPermalink
Threat Intel
Threat Intel
AboutContactPrivacyRSSJSON Feed

© 2026 Threat Intel