OX Security found 101 npm forks of the Baileys WhatsApp library, downloaded 490,000 times, that add developers' accounts to groups without consent. About a quarter of those downloads came in the last 30 days, so the campaign is still reaching new installs.
Reality
- Evidence60
- Adoption35
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
CrowdStrike says the npm stealer's author has been active since November 2022, claims bounties from at least nine companies, and that none of the stolen logs have turned up for sale. It assesses with high confidence that an LLM wrote the code.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence58
Koi Security counted 126 npm packages and more than 86,000 installs since August 2025, with 80 still live when it published. npm pulled the stealer from the attacker's host at install time. That put it outside the package a scanner reads.
Reality
- Evidence60
- Adoption35
- Hype gap+20
- Incentives55
- Confidence60
Checkmarx says a fake sorted-btree clone reached 2 million weekly downloads with clean install scripts, starting its loader only when an application calls BTree.prototype.set with a particular key. Nine related packages have been pulled.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 45%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption45
- Hype gap+20
- Incentives45
- Confidence60