101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
OX Security found 101 malicious npm packages totaling 490,000 downloads that hijack developers' WhatsApp accounts into attacker-controlled groups.
The PhantomSub campaign uses 101 malicious npm packages, collectively downloaded 490,000 times including 116,000 in the past 30 days, that abuse the open-source Baileys WhatsApp library to add victims to groups and channels without consent. OX Security identified three variants differing in how channel IDs are fetched or obfuscated, with groups largely Indonesian and selling game resources, bot scripts, and social-media boosting. The campaign builds on earlier August 2026 findings from SafeDep and Xygeni about malicious Baileys forks. Shared channel IDs and GitHub accounts link many packages to common beneficiaries.
- 101 malicious npm packages downloaded 490,000 times total
- Packages abuse Baileys WhatsApp library to subscribe victims to channels
- Three variants differ in channel-ID fetching and obfuscation
- Channels are mostly Indonesian bot-seller and game-resource markets
- Overlaps with SafeDep and Xygeni findings from August 2026
Full article530 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 29, 2026Supply Chain / Malware
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.
"The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday.
These packages have been collectively downloaded 490,000 times, out of which 116,000 occurred in the last 30 days. The names of some of the packages are below -
- ourin-baileys
- @nexustechpro/baileys
- @badzz88/baileys
- @ostyado/baileys
- levvleys
- @vanzxy/baileys
- @yudzxml/baileys
- @chatunity/baileys
- @kelvdra/baileys
- neuralwhatsapp
- lilys-baileys
- @fyxzpediaa/baileys
- noxleyss
- @xrelly-stack/bails
- alipclutch-baileys
- kurobails
- eliteprotech-baileys
- @xayz/baileys
- chromestaff-baileys
- @sanzoffc/baileys
- @sairidev/baileys-new
- cloud-baileys
- @nyzzpediaa/baileys-new
- ishumdz-bail
- nishiki-bail
- diezyclutch-baileys
- oktz-baileys
- my-auto-follow
Details of the activity first emerged in August 2026, when SafeDep said it identified a set of Baileys npm forks that were found to engage in malicious behaviors, such as stealthily making the installer's WhatsApp account follow channels the package author controls and injecting the author's advertising URL into every image and video the bot sends.
Then, earlier this month, the Xygeni Security Research Team disclosed details of another Baileys mod named "@dappaoffc/baileys-mod" that was also found to subscribe the developer's authenticated WhatsApp bot session to attacker-controlled newsletter channels.
OX Security's analysis has uncovered three different variants of the malware, each implementing different ways of handling the subscription routine -
- Variant 1 (19 packages), which fetches channel IDs from GitHub at runtime
- Variant 2 (60 packages), which embeds channel IDs in its source code in cleartext
- Variant 3 (14 packages), which embeds channel IDs in its source code in encoded and obfuscated form
One of the WhatsApp groups is assessed to be based in Indonesia and advertises accounts for mobile games and applications, such as Mobile Legends: Bang Bang and TikTok. These posts also specify a phone number that's linked to an Indonesian business WhatsApp account named "Dan."
Some of the other identified groups and channels are listed below -
- Neural (798 followers), which markets Resource Supplies (RSS) sales using JualanRSS, an online marketplace that sells in-game resources such as food, ore, stone, timber, and gold.
- MONTE – BMG (1,000 followers)
- CORTANA TECH (1,300 followers)
- Fyxzpedia.ID – Utama (4,800 followers)
"The channels we could identify are mostly small bot-seller and 'market' channels, largely Indonesian, where follower counts serve as social proof for selling bot scripts, bot-building services, 'premium' APKs and social-media boosting," OX Security said.
"Many packages in this campaign are not independent. The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers. A shared channel means a shared beneficiary: whoever owns the channel collects followers from every package that targets it, whoever published the package."
Developers are advised to check if they have been added to the WhatsApp groups, block them, configure detection rules for blocking the malicious npm Baileys packages, and refrain from using packages that require the personal WhatsApp account to be connected.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.