AI Weekly Malaysia

Back to items Summaries

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

ID
29876
Status
summarized
Published
29 Sep 2026, 9:45 PM
Fetched
29 Sep 2026, 11:59 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.0
Created
29 Sep 2026, 11:59 PM
Tags
Audience
developersvibe_codersai_agent_userssaas_founders

What happened

OX Security researchers identified 101 npm packages that abuse the open-source 'Baileys' WhatsApp library to silently add victims' WhatsApp accounts to attacker-controlled groups and channels, a campaign dubbed PhantomSub. The packages have been downloaded 490,000 times in total, with 116,000 of those downloads in the last 30 days, and split into three variants: 19 fetch channel IDs from GitHub at runtime, 60 hardcode them in cleartext, and 14 embed them encoded/obfuscated. The write-up follows earlier August 2026 SafeDep findings on malicious Baileys forks and a September Xygeni disclosure about '@dappaoffc/baileys-mod'; one of the groups is assessed to be based in Indonesia and advertises mobile-game and app accounts including Mobile Legends: Bang Bang and TikTok.

Why it matters

If you build or self-host a WhatsApp bot, the practical risk is not just a bad dependency: an already-authenticated Baileys session can be made to follow or join channels, and SafeDep's earlier finding also showed ad URLs being injected into every image and video the bot sends. Check your lockfile for any Baileys fork under a random scope or a name like 'ourin-baileys', 'noxleyss', or '@nexustechpro/baileys', and if one is present, remove it, rotate/re-link the WhatsApp session, and re-audit anything the bot posted. The 116,000 downloads in the last 30 days means these packages are still live and being pulled now, so this is a today check, not a backlog item.

Discussion angle

Scope names and fork naming conventions gave these packages a veneer of legitimacy — worth discussing what a concrete dependency-review rule looks like for a small SEA team shipping WhatsApp bots, given that the payload here is a live authenticated session rather than a stolen credential.

Top