101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.

Cybersecurity researchers have uncovered a large software supply-chain campaign involving 101 malicious npm packages designed to secretly add developers' authenticated WhatsApp accounts to attacker-controlled groups and channels.
The campaign, dubbed PhantomSub by OX Security, abuses modified versions of Baileys, an open-source JavaScript library commonly used by developers to interact with WhatsApp Web and build bots and automation tools.
Nearly 500,000 Downloads
The 101 packages have collectively accumulated approximately 490,000 downloads, including about 116,000 downloads in the last 30 days.
Some of the packages identified include:
ourin-baileys@nexustechpro/baileys@badzz88/baileys@ostyado/baileyslevvleys@vanzxy/baileys@chatunity/baileysneuralwhatsapplilys-baileyscloud-baileysmy-auto-follow
OX Security reported that only 16 of the identified packages had been removed from npm as of September 28, meaning many remained available when the research was published.
How PhantomSub Works
The malicious packages are modified forks of the legitimate Baileys WhatsApp library.
Once a developer connects an authenticated WhatsApp account, the malicious code abuses that existing session to automatically follow or join attacker-selected WhatsApp channels and groups without the account owner's permission.
The basic attack flow is:
Developer Installs Malicious npm Package → WhatsApp Account Connected → Package Uses Authenticated Session → Account Secretly Follows Attacker-Controlled Channels
Researchers identified three primary variants of the malicious code.
| Variant | Technique |
|---|---|
| Variant 1 | Fetches WhatsApp channel IDs from GitHub at runtime |
| Variant 2 | Stores channel IDs directly in source code |
| Variant 3 | Hides channel IDs using encoding and obfuscation |
The GitHub-based approach is particularly useful to attackers because they can change the targeted WhatsApp channels remotely without publishing another npm package version.
Why Attackers Want WhatsApp Followers
Unlike many malicious npm campaigns, PhantomSub does not primarily appear designed to steal cryptocurrency, passwords or developer API tokens.
Instead, researchers assess that its main purpose is artificially increasing follower numbers for WhatsApp channels and groups.
Several identified channels appear connected to Indonesian markets promoting bot scripts, game accounts, premium APKs, social-media boosting and in-game resources. Inflated follower counts can make these channels appear more popular and trustworthy to potential customers.
Researchers also found that some malicious Baileys forks could inject promotional links into images and videos sent through compromised WhatsApp bot sessions.
What Developers Should Do
Developers using unofficial Baileys forks should review their dependencies and remove suspicious packages.
Security teams should also:
- Search
package.jsonand lockfiles for known malicious packages. - Prefer the legitimate
@whiskeysockets/baileyspackage from a verified source. - Review WhatsApp accounts for unknown groups or followed channels.
- Leave and report unauthorized groups.
- Avoid connecting personal WhatsApp accounts to untrusted packages.
- Monitor Node.js applications for unexpected connections to GitHub-hosted configuration files.
- Use dependency scanning to identify malicious or suspicious npm packages.
OX Security also recommends blocking known malicious Baileys packages through dependency-security controls.
Security Takeaway
PhantomSub demonstrates that software supply-chain attacks do not always need to steal credentials or deploy traditional malware.
In this case, attackers turned trusted developer dependencies into an automated mechanism for manipulating WhatsApp accounts:
Malicious npm Package → Trusted WhatsApp Session → Unauthorized Subscription → Artificial Follower Growth
With 101 packages and roughly 490,000 downloads, the campaign highlights why developers should carefully verify unofficial forks before granting them access to authenticated accounts.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Researchers uncover malicious Terraform providers and Go modules delivering Graphalgo-linked Go malware using Slack and Ethereum blockchain infrastructure for command and control.


