101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent

Malicious npm Packages Expose Developers’ WhatsApp Accounts to Unauthorized Groups

A disturbing discovery has been made in the world of open-source software development, where 101 malicious packages were found on the popular npm registry. These packages, designed for JavaScript developers, secretly added unsuspecting users’ WhatsApp accounts to unauthorized groups without their consent. The revelation raises serious concerns about the security and trustworthiness of widely-used dependencies.

The affected packages, ranging from libraries to tools, were downloaded millions of times before being flagged by researchers at Snyk, a cybersecurity firm that monitors npm’s ecosystem. Upon further investigation, it became clear that the malicious code was designed to exploit the WhatsApp Web API, allowing attackers to append target accounts to arbitrary groups. This vulnerability stems from the fact that WhatsApp’s Web login feature uses a session cookie, which can be obtained through the affected packages.

While the scope of this issue is substantial, with 101 compromised packages and millions of potential victims, the actual risk may vary depending on individual circumstances. Developers who used these malicious packages might have unwittingly exposed their personal or professional accounts to unauthorized access. However, it’s worth noting that WhatsApp has implemented two-factor authentication for Web login, which could limit an attacker’s ability to exploit this vulnerability.

The incident serves as a stark reminder of the importance of supply chain security in software development. npm, like other package repositories, relies on the trustworthiness of its contributors and users. When malicious code is introduced into widely-used packages, it can spread quickly through the ecosystem, putting many projects at risk. This case highlights the need for developers to regularly audit their dependencies, monitor updates, and verify the integrity of their project’s environment.

In light of this incident, security-conscious developers are advised to take immediate action by reviewing their npm usage and checking if they have any packages from the affected list. Furthermore, users should be cautious when using Web login features for WhatsApp or other services that rely on similar authentication mechanisms. By staying vigilant and maintaining a secure development environment, we can minimize the risk of such vulnerabilities and protect our digital assets.

To prevent similar incidents in the future, developers are encouraged to adopt robust security practices, including dependency auditing, continuous monitoring, and regular updates. Additionally, package maintainers should prioritize code quality, testing, and peer review to ensure the integrity of their contributions. By working together, we can build a more secure software ecosystem that protects not only our projects but also our personal data and online presence.


Source: The Hacker News — 2026-09-29