A dangerous npm package named “lotusbail” has been stealing WhatsApp messages and user data from thousands of developers worldwide. The package, which has been downloaded over 56,000 times, disguises itself as a legitimate WhatsApp Web API library while secretly running malware in the background. It presents itself as a fork of the trusted “@whiskeysockets/baileys” package, […]
The post Malicious NPM Package with 56K Downloads Steals WhatsApp Messages appeared first on Cyber Security News.
Read the original article: