MikeTrendsTrends right now

✉news TechnologySoftware first seen 8 h ago, last 2 h ago, peak #23

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups

Original: 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers report that 101 malicious packages published to the npm registry have been found adding developers' WhatsApp accounts to groups without their consent. The packages, disguised as legitimate libraries, harvest phone numbers from developer environments and enroll them into unauthorized WhatsApp groups, likely for spam or scam distribution. The incident highlights ongoing supply chain risks in the npm ecosystem, where attackers continue to abuse open-source package repositories to target software developers.

Why now: The discovery of a novel supply chain attack abusing WhatsApp is raising alarm among developers about open-source package security.

npmWhatsAppThe Hacker News

Open on news →

Rank over time, top of the chart is #1. 5 snapshots from 8 h ago to 2 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/392470