npm Ecosystem — 101 Malicious Packages Add Developers’ WhatsApp Accounts to Groups Without Consent

Publication date: September 29, 2026
Category: Supply Chain / Malware

Introduction

Security researchers have identified a cluster of 101 malicious packages published in the official Node Package Manager (npm) registry designed to trap software developers in a mass subscription campaign targeting WhatsApp groups and channels, dubbed PhantomSub. These malicious software components, which collectively exceed 490,000 historical downloads and have accumulated approximately 116,000 recent downloads within a thirty-day window, abuse automation integrations to hijack victims’ messaging sessions. This discovery highlights once again the critical vulnerability of Open Source Software (OSS) supply chains, where the impersonation of legitimate dependencies allows threat actors to compromise local infrastructure and software engineers’ personal accounts.

What is PhantomSub? (General Analysis)

PhantomSub represents a sophisticated software supply chain poisoning campaign aimed at manipulating social media metrics and amplifying underground marketing platforms. The primary attack vector involves publishing malicious packages on npm that mimic or fork legitimate projects related to Baileys, a widely used multi-platform JavaScript library designed to interact with the WhatsApp web API.

When a developer installs these contaminated dependencies in their local testing or development environments, the code executes hidden routines that exploit the user’s authenticated WhatsApp session to force their adherence to attacker-controlled broadcast channels and chat groups. From a threat classification perspective, this behavior aligns with Software Supply Chain Compromise combined with clickjacking and social proof manipulation techniques.

  • Estimated CVSS Score: 6.5 (Medium) — Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N (Reasoned estimation given the absence of a formal CVE identifier assigned at the time of reporting).
  • Estimated CWE Classification: CWE-506 (Embedded Malicious Code) and CWE-494 (Download of Code Without Integrity Check).

How Does It Work? (Technical Analysis)

The analysis conducted on the malicious cluster broke down the operation into three distinct architectural variants that determine how the automated subscription routines are retrieved and executed:

  • Initial Infection Flow and Entry: The developer incorporates the malicious package (for example, variants under names such as ourin-baileys, @nexustechpro/baileys, or levvleys) into their package.json file, believing it to be a utility tool or a legitimate Baileys client. Upon running the application or initializing the test script, the WhatsApp bot initialization logic is deployed.
  • Persistence Mechanisms and Code Execution: Taking advantage of the fact that the Baileys library requires storing active session credentials (authentication tokens linked via QR codes), the malware hijacks the execution context. Instead of operating purely as a development interface, the code injects internal requests toward the WhatsApp API to simulate user actions.
  • Communication with External Infrastructure (C2) and Variants:
    • Variant 1 (19 packages): Fetches malicious channel and group identifiers directly from public GitHub repositories in real time during script execution.
    • Variant 2 (60 packages): Embeds channel identifiers directly into the source code in cleartext, facilitating rapid execution without initial external network dependencies.
    • Variant 3 (14 packages): Conceals channel identifiers using obfuscation and encoding techniques within the source code to evade automated static analysis based on cleartext signatures.

“Many packages in this campaign are not independent. The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers. A shared channel means a shared beneficiary: whoever owns the channel collects followers from every package that targets it…”

Affected Systems / Environments

The impact of this campaign is concentrated on the following profiles and technological components:

  • Affected Ecosystem: JavaScript/TypeScript developers utilizing the npm package manager and WhatsApp automation dependencies.
  • Compromised Base Libraries: Forks and modifications of the Baileys framework, including fraudulent nomenclature and deceptive names detected across more than a hundred variants.
  • Spam Destination Platforms: Messaging channels and groups primarily—though not exclusively—oriented toward regions in Indonesia, utilized for commercializing mobile gaming resources (such as Mobile Legends: Bang Bang), bot scripts, and artificial social media metric boosting services.

Mitigation and Detection

Remediation

  • Dependency Review: Audit package.json and package-lock.json files in development projects to identify and purge unverified packages related to baileys, especially those originating from unknown publishers or dubious forks.
  • WhatsApp Account Verification: Immediately check the WhatsApp mobile application to determine if the developer’s personal or testing account has been unilaterally added to unknown groups; proceed to leave them and block the associated numbers.
  • Credential Isolation: Avoid connecting primary personal WhatsApp accounts to local development environments that utilize un-audited third-party automation libraries.

Detection

  • Network and Endpoint Monitoring: Implement static analysis rules in CI/CD pipelines to detect calls to unauthorized external GitHub repositories during npm dependency installation (npm install).
  • Indicator of Compromise (IoCs) Search Rule: Monitor for the presence of identified packages in internal security audits using dependency scanners.
json
{
  "rule_name": "Detect_Malicious_Baileys_Supply_Chain",
  "description": "Searches for package names associated with the PhantomSub campaign in npm dependencies",
  "pattern": "(ourin-baileys|@nexustechpro/baileys|@badzz88/baileys|@ostyado/baileys|levvleys|@vanzxy/baileys|@yudzxml/baileys|@chatunity/baileys|@kelvdra/baileys|neuralwhatsapp|lilys-baileys|@fyxzpediaa/baileys|noxleyss|@xrelly-stack/bails|alipclutch-baileys|kurobails|eliteprotech-baileys|@xayz/baileys|chromestaff-baileys|@sanzoffc/baileys|@sairidev/baileys-new|cloud-baileys|@nyzzpediaa/baileys-new|ishumdz-bail|nishiki-bail|diezyclutch-baileys|oktz-baileys|my-auto-follow)"
}

Wrapping Up

The PhantomSub campaign highlights persistent risks within the open-source software supply chain, where popular automation libraries are impersonated to execute automated malicious actions in the background. By exploiting developers’ trust and abusing authenticated messaging sessions, attackers artificially inflate channel metrics for commercial and spam purposes. Adopting stringent dependency management policies and continuously auditing development environments are indispensable defenses to mitigate this type of supply chain attack vector.

References