Threat Advisories:
🎧 Podcast: This Month's Threats in 10 Min! Emerging Threat Intel Audio Briefing - Listen & Defend Now →
👥 Play Count: Loading...

Malicious npm Packages Target WhatsApp Developers with Kill Switch

Amber | Attack Report
Download PDF

Two malicious npm packages, naya-flore and nvlore-hsc, have been uncovered targeting developers building WhatsApp integrations. Masquerading as legitimate socket libraries, these packages secretly contain a remote-controlled kill switch that wipes a developer’s system if their phone number isn’t found in a whitelist stored on a GitHub repository. When an unapproved number is detected, the package silently executes a destructive command that deletes all files. Although the code also includes functionality for device data exfiltration, it appears the attacker ultimately focused on system destruction. This incident marks a troubling shift in supply chain attacks, demonstrating a new level of precision where even niche developer communities are being deliberately and selectively targeted.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox