Lotusbail is a malicious npm package (trojanized dependency) masquerading as a WhatsApp Web API library and presented as a fork/wrapper of the legitimate Baileys / @whiskeysockets/baileys project. It was available on npm for roughly six months (uploaded May 2025) and accumulated >56,000 downloads. The package provides real WhatsApp integration functionality to evade suspicion and static/reputation-based detection.
Capabilities and behavior (as described):
Infection vector / targeting:
Attribution / reporting:
Known indicators of compromise:
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious npm package (supply-chain) posing as a WhatsApp Web API library; intercepts messages and steals session/authentication data, contacts, and media by tampering with WebSocket traffic and hijacking device pairing.
Lotusbail is a malicious NPM package masquerading as a WhatsApp Web API library. It intercepts WhatsApp credentials, messages, contacts, and media, exfiltrates them using custom RSA encryption, and installs a persistent backdoor by hijacking the device pairing process. It employs anti-debugging techniques and obfuscation to evade detection, representing a sophisticated supply chain attack.
lotusbail is a malicious NPM package that masquerades as a legitimate WhatsApp library. It hijacks WhatsApp accounts, steals private data (contacts, media, messages, authentication tokens), and maintains persistent backdoor access by linking the attacker's device to the victim's WhatsApp account. It uses custom RSA encryption to exfiltrate data and includes anti-analysis traps to hinder investigation.
LotusBail is a stealer malware distributed as a fake WhatsApp API, designed to exfiltrate sensitive information from developers who download and use it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.