101 Malicious npm Packages Hijack WhatsApp Accounts via 'PhantomSub' Campaign
Researchers uncover 101 malicious npm packages exploiting the 'Baileys' WhatsApp project to forcibly add developers to unwanted WhatsApp groups in the 'PhantomSub' campaign.

Cybersecurity researchers have identified a significant campaign involving 101 malicious npm packages designed to ensnare developers into WhatsApp groups without their consent. Dubbed 'PhantomSub,' this operation leverages the open-source 'Baileys' WhatsApp project to achieve its goals, adding unsuspecting users to various groups and channels.
According to OX Security researchers, these malicious packages abuse the 'Baileys' library to automatically add victims to groups. The scale of the operation is considerable, with the packages collectively downloaded approximately 490,000 times. Notably, a substantial portion of these downloads, around 116,000, occurred within the last 30 days, indicating recent and ongoing activity.
The campaign's methodology has evolved, with researchers identifying three distinct variants of the malware. The first variant, comprising 19 packages, dynamically fetches channel IDs from GitHub at runtime. A larger group of 60 packages embeds these channel IDs directly within their source code in cleartext, making them easier to detect. The third variant, consisting of 14 packages, employs encoded and obfuscated methods to hide the channel IDs within the source code, presenting a more sophisticated evasion technique.
Details of similar malicious activities involving Baileys forks first emerged in August 2026, when SafeDep reported on packages that not only subscribed users to attacker-controlled channels but also injected advertising URLs into bot-sent messages. More recently, the Xygeni Security Research Team disclosed another Baileys modification, '@dappaoffc/baileys-mod,' which similarly subscribed authenticated WhatsApp bot sessions to malicious newsletter channels.
The identified WhatsApp groups and channels appear to be primarily focused on marketing and sales, often related to in-game resources, bot scripts, and 'premium' APKs. One group, assessed to be based in Indonesia, advertises mobile games and applications and is linked to an Indonesian business WhatsApp account named 'Dan.' Other identified channels include 'Neural' (798 followers), 'MONTE – BMG' (1,000 followers), 'CORTANA TECH' (1,300 followers), and 'Fyxzpedia.ID – Utama' (4,800 followers).
Researchers observed a high degree of interconnectedness among the malicious packages. Many do not operate independently, with shared channel IDs, remote channel lists, and GitHub accounts appearing across packages with different names and publishers. This suggests a centralized beneficiary who collects followers from every package targeting their associated channel, effectively consolidating reach and influence.
Developers are strongly advised to exercise caution when using npm packages, especially those related to WhatsApp or requiring personal account integration. It is recommended to review downloaded packages, block any suspicious WhatsApp groups, and implement detection rules to identify and prevent the use of malicious Baileys npm packages. The PhantomSub campaign highlights the persistent threat of supply-chain attacks within the open-source ecosystem.