PhantomSub Campaign: 101 Malicious npm Packages Hijack WhatsApp Accounts
Cybersecurity researchers have uncovered a widespread campaign, dubbed **PhantomSub**, involving 101 malicious npm packages. These packages exploit the 'Baileys' open-source project to stealthily subscribe developers' WhatsApp accounts to attacker-controlled groups and channels without consent, accumulating nearly half a million downloads.
Cybersecurity researchers at **OX Security** have identified a cluster of 101 npm packages designed to ensnare developers in a WhatsApp group subscriber campaign known as **PhantomSub**.
"The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," stated **Nir Zadok**, **Moshe Siman Tov Bustan**, and **Vitalii Chepurko** of OX Security in a recent technical write-up.
These deceptive packages have collectively amassed approximately 490,000 downloads, with a significant 116,000 occurring in the last 30 days. Some of the identified package names include:
* ourin-baileys
* @nexustechpro/baileys
* @badzz88/baileys
* @ostyado/baileys
* levvleys
* @vanzxy/baileys
* @yudzxml/baileys
* @chatunity/baileys
* @kelvdra/baileys
* neuralwhatsapp
* lilys-baileys
* @fyxzpediaa/baileys
* noxleyss
* @xrelly-stack/bails
* alipclutch-baileys
* kurobails
* eliteprotech-baileys
* @xayz/baileys
* chromestaff-baileys
* @sanzoffc/baileys
* @sairidev/baileys-new
* cloud-baileys
* @nyzzpediaa/baileys-new
* ishumdz-bail
* nishiki-bail
* diezyclutch-baileys
* oktz-baileys
* my-auto-follow
### Prior Discoveries and Evolving Tactics
Early indications of this activity emerged in August 2026 (sic), when **SafeDep** reported identifying **Baileys** npm forks engaged in malicious behaviors. These included stealthily making the installer's WhatsApp account follow channels controlled by the package author and injecting the author's advertising URL into images and videos sent by the bot.
More recently, the **Xygeni Security Research Team** disclosed details of another **Baileys** mod, "**@dappaoffc/baileys-mod**," which also subscribed developers' authenticated WhatsApp bot sessions to attacker-controlled newsletter channels.
### Malware Variants and Campaign Scope
OX Security's analysis revealed three distinct malware variants, each employing different methods for the subscription routine:
* **Variant 1 (19 packages):** Fetches channel IDs from **GitHub** at runtime.
* **Variant 2 (60 packages):** Embeds channel IDs in its source code in cleartext.
* **Variant 3 (14 packages):** Embeds channel IDs in its source code in an encoded and obfuscated form.
One of the identified WhatsApp groups, believed to be based in Indonesia, promotes accounts for mobile games and applications like **Mobile Legends: Bang Bang** and **TikTok**. These posts often include a phone number linked to an Indonesian business WhatsApp account named "Dan."
Other groups and channels identified include:
* **Neural (798 followers):** Markets Resource Supplies (RSS) sales via **JualanRSS**, an online marketplace for in-game resources.
* **MONTE β BMG (1,000 followers)**
* **CORTANA TECH (1,300 followers)**
* **Fyxzpedia.ID β Utama (4,800 followers)**
"The channels we could identify are mostly small bot-seller and 'market' channels, largely Indonesian, where follower counts serve as social proof for selling bot scripts, bot-building services, 'premium' APKs and social-media boosting," OX Security elaborated.
### Shared Infrastructure and Recommendations
The researchers noted that many packages within this campaign are interconnected, sharing channel IDs, remote channel lists, and **GitHub** accounts across different package names and publishers. This shared infrastructure points to a common beneficiary collecting followers from every targeted package.
Developers are strongly advised to:
* Check their WhatsApp accounts for unauthorized group subscriptions and block any identified malicious groups.
* Configure detection rules to block these malicious npm **Baileys** packages.
* Exercise caution and refrain from using packages that require connecting a personal WhatsApp account.