Two malicious npm packages, naya-flore and nvlore-hsc, have been uncovered targeting developers building WhatsApp integrations. Masquerading as legitimate socket libraries, these packages secretly contain a remote-controlled kill switch that wipes a developer’s system if their phone number isn’t found in a whitelist stored on a GitHub repository. When an unapproved number is detected, the package silently executes a destructive command that deletes all files. Although the code also includes functionality for device data exfiltration, it appears the attacker ultimately focused on system destruction. This incident marks a troubling shift in supply chain attacks, demonstrating a new level of precision where even niche developer communities are being deliberately and selectively targeted.
Get through updates and upcoming events, and more directly in your inbox