Malicious npm Packages Enrol Developers in WhatsApp Groups

Security researchers have identified 101 malicious npm packages that use the Baileys open-source WhatsApp project to add developers’ authenticated WhatsApp accounts to groups without consent. OX Security has named the subscriber-farming campaign PhantomSub and said the packages have been downloaded about 490,000 times, including 116,000 downloads in the last 30 days.
The activity targets developers who install packages presented as Baileys forks or related tools. Once a developer connects a WhatsApp account for a bot session, the altered package can use that authenticated session to subscribe the account to attacker-controlled groups or channels.
Three package variants implement the subscription routine
OX Security identified three malware variants. The first, found in 19 packages, retrieves channel identifiers from GitHub during execution. A second variant, present in 60 packages, stores those identifiers in clear text within its source code. A third variant, found in 14 packages, embeds the identifiers in encoded and obfuscated form.
The differing implementations point to the same operational goal: adding accounts to channels whose operators benefit from a larger audience. Researchers observed repeated use of the same channel IDs, remote channel lists and GitHub accounts across packages released under different names and publishers. OX Security said that overlap indicates a shared beneficiary collecting followers from each package directed at the same channels.
Campaign builds on earlier Baileys abuse
SafeDep reported in August 2026 that some Baileys npm forks silently made installers’ WhatsApp accounts follow channels controlled by package authors. Those packages also injected an author’s advertising URL into images and videos sent by the bot. Earlier this month, the Xygeni Security Research Team described @dappaoffc/baileys-mod, another modified Baileys package that subscribed authenticated bot sessions to attacker-controlled newsletter channels.
Among the groups identified in the newer campaign, one is assessed as Indonesian and advertises accounts for Mobile Legends: Bang Bang and TikTok. The posts include a number connected to an Indonesian business WhatsApp account called “Dan.” Other named channels include Neural, MONTE – BMG, CORTANA TECH and Fyxzpedia.ID – Utama. OX Security described the identified channels as mostly small Indonesian bot-seller and market channels, where follower counts are used as social proof for sales of bot scripts, bot-building services, premium APKs and social-media boosting.
Dependency checks should include account-side effects
Package names alone are not a reliable safeguard because the campaign spans different publishers and names. Developers should check whether their accounts have been added to these groups, block the groups where necessary and configure detection rules to block the malicious npm Baileys packages.
For teams using WhatsApp automation, the practical implication is to review dependencies before connecting an account, especially personal accounts, and avoid packages that require that connection unless their code and provenance have been vetted.

