WhatsApp Developer Community Under Attack: Malicious NPM Packages Deploy Devastating Data Wipers

Listen to this Post

Featured Image

Rising Threat Hidden in Popular Developer Tools

Two newly discovered malicious NPM packages have sparked serious concern in the WhatsApp developer community, posing as legitimate libraries but hiding destructive data-wiping code. Security researchers at Socket revealed that these packages — naya-flore and nvlore-hsc — have been downloaded more than 1,100 times since their release last month. Marketed as WhatsApp socket libraries, these tools were designed to appeal to developers working with WhatsApp Business API and automation solutions. However, instead of streamlining development, they can silently execute a complete wipe of a developer’s files.

Even more alarming, the malicious publisher known as nayflore remains active on the NPM registry, with several other packages still live, including nouku-search, very-nay, naya-clone, node-smsk, and @veryflore/disc. While these currently appear safe, experts warn that they could be weaponized at any moment through a hidden update. This incident underscores a growing pattern of cybercriminals targeting high-demand developer tools to inflict maximum disruption.

The malicious code operates under the guise of a function called requestPairingCode, supposedly intended for WhatsApp pairing. In reality, it downloads a base64-encoded JSON file from GitHub containing a list of Indonesian phone numbers. Anyone on this list is spared, but all others face a devastating command — rm -rf — which recursively deletes every file in the current directory, potentially destroying entire projects in seconds.

Researchers also identified a dormant data exfiltration function named generateCreeds within both packages. Although currently disabled, it’s capable of stealing a victim’s phone number, device ID, account status, and hardcoded keys, further raising the risk profile of these tools.

The threat isn’t confined to JavaScript. Socket’s investigation also uncovered 11 malicious Go packages employing obfuscated code to download and execute remote payloads in memory. These target both Linux CI servers and Windows machines, often using typosquatting — subtle misspellings of popular package names — to trick developers into installing them. Among these are github.com/stripedconsu/linker, github.com/expertsandba/opt, and github.com/lastnymph/gouid, many of which remain publicly available.

The incidents highlight the persistent dangers of supply chain attacks in open-source ecosystems. Developers are urged to vet all dependencies, verify publishers, and monitor package updates closely, as the convenience of community-driven libraries comes with an ever-increasing security cost.

What Undercode Say:

This case is a textbook example of software supply chain infiltration, a growing vector for cyberattacks that exploit the trust developers place in open-source repositories. In the past, malicious packages often aimed at crypto miners or credential theft, but here we see a particularly destructive tactic — direct data wiping — designed not for profit, but for pure sabotage.

From a strategic perspective, targeting WhatsApp-related libraries is shrewd. The WhatsApp Cloud API has seen a surge in adoption as businesses integrate it for customer communication, creating a ripe opportunity for attackers to slip malicious code into tools developers are actively searching for. By disguising these packages as legitimate socket libraries, the attackers increased their odds of being installed by unsuspecting victims.

The inclusion of a geographic “kill switch” using Indonesian phone numbers suggests this campaign may have a regional origin or motive. It indicates that the attackers want to avoid harming individuals within a certain demographic, while targeting the broader global developer community. This selective targeting is increasingly common in modern malware campaigns, as it helps avoid unwanted attention from local authorities or specific threat groups.

Equally concerning is the commented-out data exfiltration function. Even though inactive, it signals that these tools could evolve beyond destruction into targeted espionage. This dormant capability is a classic “sleeper” tactic, where malicious code is left disabled until activated in a future update or campaign phase.

The parallel discovery of malicious Go packages shows that this attack is not isolated to one language ecosystem. The Go language is heavily used for backend services, DevOps tooling, and CI/CD pipelines, meaning a successful compromise could affect entire infrastructure environments. The use of typosquatting further capitalizes on human error, a simple yet effective social engineering approach.

From a security standpoint, these events reinforce three critical lessons:

  1. Dependency auditing is non-negotiable — developers must use tools to verify integrity before installation.
  2. Publisher identity matters — new or little-known publishers with many packages should be treated with caution.
  3. Real-time monitoring — security tools like Socket can detect malicious behavior patterns before major damage occurs.

Ultimately, this wave of attacks signals that developer environments are now a primary cyber battleground. The convenience of open-source comes with a steep security trade-off, and attackers are leveraging that trust gap with alarming precision. Without proactive defense, these incidents could escalate into widespread disruption, especially as automation and CI/CD systems become more integral to business operations.

🔍 Fact Checker Results:

✅ Confirmed: NPM packages naya-flore and nvlore-hsc are malicious and deploy file-wiping commands.

✅ Confirmed: Downloads exceeded 1,100 before discovery.

❌ Not Verified: Motive or origin of the attackers — no conclusive attribution yet.

📊 Prediction:

If these malicious package campaigns continue unchecked, we will likely see more sophisticated, multi-stage payloads embedded in developer tools, including ransomware components and active data exfiltration. Within the next 12 months, attackers may increasingly exploit trusted package ecosystems not only for destruction but also for targeted espionage in high-value corporate environments.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.quora.com/topic/Technology
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon