101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.

“The malicious packages abuse the ‘Baileys’ WhatsApp open source project to add the victims to groups without their consent,” OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Bootimus – A Self-Contained PXE and HTTP Boot Server

Bootimus – A Self-Contained PXE and HTTP Boot Server Source: Hacker News

Why current LLM costs are not sustainable

Why current LLM costs are not sustainable Source: Hacker News

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and