HomeSecurityFake WhatsApp API package on npm steals messages

Fake WhatsApp API package on npm steals messages

Cybersecurity researchers have revealed details of a new malicious package in the npm repository, which acts as a fully functional WhatsApp API, while also having the ability to intercept every message and connect the attacker's device to the victim's WhatsApp account.

WhatsApp

The package, called “lotusbail”, has been downloaded over 56,000 times and was uploaded to the registry by a user named “seiren_primrose” (in May 2025). Of the 56,000, 711 downloads were made in the last week. The library remains available for download at the time of writing.

Fake WhatsApp API Package: How does the malware work?

Under the guise of a functional tool, the malware “steals your WhatsApp credentials, intercepts every message, collects your contacts, installs a persistent backdoor , and encrypts everything before sending it to the attacker’s server,” according to Koi Security researcher Tuval Admoni. Specifically, it is designed to capture authentication tokens and session keys,message history, contact lists with phone numbers, as well as media files and documents.

See also: MacSync Stealer bypasses Apple's malware protections

Fake WhatsApp API package on npm steals messages

The library is inspired by @whiskeysockets/baileys, a legitimate WebSockets-based TypeScript for interacting with the WhatsApp Web API. This is achieved through a malicious WebSocket wrapper that routes authentication information and messages, allowing it to record credentials and conversations. The stolen data is transmitted to a URL controlled by the attacker (in encrypted form).

The attack is further expanded, as the package also includes hidden functionality to create persistent access to WhatsApp the victim's device pairing process using a hard-coded pairing code. "When you use this library for authentication, you're not just pairing your app - you're also pairing the attacker's device," Admoni said. "They have full, persistent access to your WhatsApp account, and you have no idea it's there."

See also: Wonderland: Android malware combines dropper, SMS theft and RAT capabilities

By connecting the attacker's device to the target's WhatsApp, not only is continuous access to contacts and conversations, but it also allows persistent access even after the package is uninstalled, as the attacker's device remains connected to the WhatsApp account until disconnected via the app's settings.

Fake WhatsApp API package on npm steals messages

Furthermore, the fake WhatsApp API package is equipped with anti-debugging that cause it to enter an infinite loop trap when debugging tools are detected, freezing execution.

See also: RansomHouse RaaS: New dangerous capabilities

“Supply chain attacks aren’t slowing down – they’re getting better,” Koi noted. “Traditional security doesn’t detect this. Static analysis sees WhatsApp working code and approves it. Reputation systems have seen 56,000 downloads and trust it. Malware hides in the gap between ‘this code works’ and ‘this code only does what it claims.’”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS