NPM Package With 56K Downloads Caught Stealing WhatsApp Messages
The lotusbail npm package, designed as a WhatsApp Web API library, conceals sophisticated malware that steals user credentials and messages. Despite its legitimate appearance, it creates backdoor access to WhatsApp accounts, highlighting the need for enhanced security measures against refined supply chain attacks.