Back to Feed
MalwareSep 29, 2026

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

101 malicious npm packages were found to add developers to WhatsApp groups without consent.

Summary

Cybersecurity researchers have discovered 101 malicious npm packages that subscribe developers to WhatsApp groups without their knowledge or consent, a campaign dubbed PhantomSub. These packages leverage the open-source 'Baileys' project to achieve this, with some having been downloaded hundreds of thousands of times. The campaign appears to be primarily focused on marketing bot-seller channels and in-game resources, with many of the identified groups based in Indonesia.

Full text

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent Ravie LakshmananSep 29, 2026Supply Chain / Malware Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday. These packages have been collectively downloaded 490,000 times, out of which 116,000 occurred in the last 30 days. The names of some of the packages are below - ourin-baileys @nexustechpro/baileys @badzz88/baileys @ostyado/baileys levvleys @vanzxy/baileys @yudzxml/baileys @chatunity/baileys @kelvdra/baileys neuralwhatsapp lilys-baileys @fyxzpediaa/baileys noxleyss @xrelly-stack/bails alipclutch-baileys kurobails eliteprotech-baileys @xayz/baileys chromestaff-baileys @sanzoffc/baileys @sairidev/baileys-new cloud-baileys @nyzzpediaa/baileys-new ishumdz-bail nishiki-bail diezyclutch-baileys oktz-baileys my-auto-follow Details of the activity first emerged in August 2026, when SafeDep said it identified a set of Baileys npm forks that were found to engage in malicious behaviors, such as stealthily making the installer's WhatsApp account follow channels the package author controls and injecting the author's advertising URL into every image and video the bot sends. Then, earlier this month, the Xygeni Security Research Team disclosed details of another Baileys mod named "@dappaoffc/baileys-mod" that was also found to subscribe the developer's authenticated WhatsApp bot session to attacker-controlled newsletter channels. OX Security's analysis has uncovered three different variants of the malware, each implementing different ways of handling the subscription routine - Variant 1 (19 packages), which fetches channel IDs from GitHub at runtime Variant 2 (60 packages), which embeds channel IDs in its source code in cleartext Variant 3 (14 packages), which embeds channel IDs in its source code in encoded and obfuscated form One of the WhatsApp groups is assessed to be based in Indonesia and advertises accounts for mobile games and applications, such as Mobile Legends: Bang Bang and TikTok. These posts also specify a phone number that's linked to an Indonesian business WhatsApp account named "Dan." Some of the other identified groups and channels are listed below - Neural (798 followers), which markets Resource Supplies (RSS) sales using JualanRSS, an online marketplace that sells in-game resources such as food, ore, stone, timber, and gold. MONTE – BMG (1,000 followers) CORTANA TECH (1,300 followers) Fyxzpedia.ID – Utama (4,800 followers) "The channels we could identify are mostly small bot-seller and 'market' channels, largely Indonesian, where follower counts serve as social proof for selling bot scripts, bot-building services, 'premium' APKs and social-media boosting," OX Security said. "Many packages in this campaign are not independent. The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers. A shared channel means a shared beneficiary: whoever owns the channel collects followers from every package that targets it, whoever published the package." Developers are advised to check if they have been added to the WhatsApp groups, block them, configure detection rules for blocking the malicious npm Baileys packages, and refrain from using packages that require the personal WhatsApp account to be connected. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Malware, Open Source Security, Supply Chain, WhatsApp Tag Pairs ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header

Indicators of Compromise

  • malware — PhantomSub

Entities

npm (product)WhatsApp (technology)Baileys (product)OX Security (vendor)