101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
The Hacker News published a report titled "101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent." According to the headline and the available source text, the incident involves 101 packages published to npm, the JavaScript package registry, and the reported behavior is that these packages add developers' WhatsApp accounts to groups without the account holders' consent. The source frames the packages as malicious and links them to unauthorized changes in WhatsApp group membership for developers. The excerpt provides no additional specifics: it does not name the packages, their maintainers, the versions involved, the mechanism used to interact with WhatsApp, the groups joined, or any response from npm or WhatsApp. It also does not state whether the packages remain available, whether any accounts were affected beyond the described group additions, or what data, if any, was accessed. The only concrete figures present are the count of 101 packages and the platform names npm and WhatsApp.
Developers who installed these npm packages may have had their WhatsApp accounts added to groups without consent, per the source.