✉news TechnologySoftware first seen 10 h ago, last 37 min ago, peak #23
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups
Original: 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers report that 101 malicious packages published to the npm registry have been found adding developers' WhatsApp accounts to groups without their consent. The packages, disguised as legitimate libraries, harvest phone numbers from developer environments and enroll them into unauthorized WhatsApp groups, likely for spam or scam distribution. The incident highlights ongoing supply chain risks in the npm ecosystem, where attackers continue to abuse open-source package repositories to target software developers.
Why now: The discovery of a novel supply chain attack abusing WhatsApp is raising alarm among developers about open-source package security.
Rank over time, top of the chart is #1. 6 snapshots from 10 h ago to 37 min ago.
Evidence
- 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent · thehackernews.com
API: https://socialmediatrends-api.osmike.com/v1/trends/392470