Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens
December 22, 2025Ravie LakshmananMalware / Open Source / Supply Chain Security The Rising Tide of Malicious Packages: A Looming Threat to Software Supply Chains The recent discovery of “lotusbail,” a malicious npm package masquerading as a WhatsApp API, and a wave of compromised NuGet packages targeting the cryptocurrency ecosystem, aren’t isolated incidents. They represent a … Read more