WhatsApp API worked exactly as promised, and stole everything

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A malicious npm package called "lotusbail" masqueraded as a legitimate WhatsApp Web API library for six months, accumulating over 56,000 downloads. The package functioned correctly while secretly stealing messages, credentials, and contact data through a proxy layer that intercepted all operations. It used four layers of

4m read timeFrom infoworld.com
Post cover image
5 Comments

Sort: