And it's especially dangerous because the code works A malicious npm package with more than 56,000 downloads masquerades as a ...
The so-called GhostPairing scam takes advantage of legitimate features in order to trick WhatsApp users into linking their ...
A malicious npm package posing as a WhatsApp API intercepts messages, steals credentials, and links attacker devices after 56 ...
Over the past six months, the fake package has reportedly been downloaded more than 56,000 times., Technology & Science, ...
Threat actors are abusing the legitimate device-linking feature to hijack WhatsApp accounts via pairing codes in a campaign ...
The lotusbail NPM package steals WhatsApp credentials, messages, and contacts, and provides persistent access to the victims’ accounts.
WhatsApp today is much more than just a messaging app—it’s used for money transfers, video calls, and sharing important ...
Cybersecurity experts warn of a WhatsApp scam that silently hijacks accounts using device-linking features, letting attackers ...
Device-level protection plays a key role as well. Users should enable app lock and chat lock to prevent unauthorised access, especially if the phone is lost or borrowed. Using fingerprint unlock, Face ...
A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal ...
WhatsApp users are being warned about a new form of account hijacking that exploits the platform's legitimate device-linking ...
Security researchers have discovered a critical vulnerability with WhatsApp that exposes the phone numbers of more than 3 billion users worldwide. The privacy flaw could be used by cyber criminals to ...