It has been found that two malicious NPM packages masquerading as WhatsApp development tools use destructive data-wiping malware to recursively remove files from developers’ machines.
There are now two malicious NPM packages in the registry that use harmful data-wiping malware to target WhatsApp developers. Since their release last month, the packages—which were uncovered by Socket researchers—have been downloaded more than 1,100 times. They pose as WhatsApp socket libraries.
At the time of writing, both are still accessible even though Socket had flagged the publisher, Nayflore, and sent takedown requests. Although the same publisher has submitted other packages to NPM, including nouku-search, very-nay, naya-clone, node-smsk, and @veryflore/disc, the two malicious packages are called naya-flore and nvlore-hsc.
Even though these extra five packages aren’t harmful right now, it’s still advisable to exercise cautious because any upgrade could introduce harmful code. These packages all imitate the official WhatsApp developer libraries that are used to create automation tools read more about Fake WhatsApp developer libraries hide destructive data-wiping code.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
