A malicious package named lotusbail was discovered on the npm registry, masquerading as a legitimate WhatsApp Web API library. The package, a fork of the popular WhiskeySockets Baileys project, provides full WhatsApp API functionality while secretly stealing authentication tokens, session keys, messages, contact lists, media files, and documents from users. Researchers at Koi Security found that the package uses a malicious WebSocket wrapper to intercept all data passing through, encrypts the stolen information using multiple obfuscation techniques, and exfiltrates it to attacker-controlled servers.
In addition to data theft, lotusbail implements a covert device pairing process, linking the attacker's device to the victim's WhatsApp account and granting persistent access even after the malicious package is removed. The package has been available on npm for at least six months, accumulating over 56,000 downloads, and employs advanced anti-analysis techniques such as infinite loop traps to evade detection. Victims must manually remove unauthorized devices from their WhatsApp settings to revoke attacker access.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
As of the latest reporting, the malicious 'lotusbail' package was still available for download on npm despite public disclosure of its behavior. One report noted GitHub had not yet responded to inquiries about the package's status.
ReversingLabs publicly reported a set of 14 malicious NuGet packages targeting the cryptocurrency ecosystem, expanding awareness of parallel software supply-chain activity beyond npm. The disclosure highlighted theft of crypto assets, private keys, and Google Ads OAuth credentials.
Public reporting disclosed that the package used multiple layers of obfuscation, custom RSA encryption, compression, AES, and 27 infinite-loop anti-debugging traps to hinder analysis and conceal exfiltration. Researchers emphasized that runtime behavioral monitoring was needed because static code review and reputation checks could miss the threat.
Koi Security researchers identified that 'lotusbail' had been downloaded more than 56,000 times and was intercepting messages, authentication tokens, contacts, media, and documents from developer environments. They found the package also abused WhatsApp multi-device pairing to keep attacker access even after the package was removed.
A separate supply-chain campaign involving 14 malicious NuGet packages impersonating cryptocurrency-related libraries began operating in the wild. The packages were used to steal funds, private keys, and Google Ads OAuth credentials while inflating trust through fake popularity signals and rapid versioning.
The trojanized npm package 'lotusbail,' masquerading as a WhatsApp Web API library based on the legitimate Baileys project, was available on npm starting around May 2025. It provided real functionality while secretly stealing WhatsApp data and enabling persistent account access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcehackread.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.