101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
- ID
- 29876
- Status
- summarized
- Published
- 29 Sep 2026, 9:45 PM
- Fetched
- 29 Sep 2026, 11:59 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 29 Sep 2026, 11:59 PM
- Tags
- Audience
- developersvibe_codersai_agent_userssaas_founders
What happened
OX Security researchers identified 101 npm packages that abuse the open-source 'Baileys' WhatsApp library to silently add victims' WhatsApp accounts to attacker-controlled groups and channels, a campaign dubbed PhantomSub. The packages have been downloaded 490,000 times in total, with 116,000 of those downloads in the last 30 days, and split into three variants: 19 fetch channel IDs from GitHub at runtime, 60 hardcode them in cleartext, and 14 embed them encoded/obfuscated. The write-up follows earlier August 2026 SafeDep findings on malicious Baileys forks and a September Xygeni disclosure about '@dappaoffc/baileys-mod'; one of the groups is assessed to be based in Indonesia and advertises mobile-game and app accounts including Mobile Legends: Bang Bang and TikTok.
Why it matters
If you build or self-host a WhatsApp bot, the practical risk is not just a bad dependency: an already-authenticated Baileys session can be made to follow or join channels, and SafeDep's earlier finding also showed ad URLs being injected into every image and video the bot sends. Check your lockfile for any Baileys fork under a random scope or a name like 'ourin-baileys', 'noxleyss', or '@nexustechpro/baileys', and if one is present, remove it, rotate/re-link the WhatsApp session, and re-audit anything the bot posted. The 116,000 downloads in the last 30 days means these packages are still live and being pulled now, so this is a today check, not a backlog item.
Discussion angle
Scope names and fork naming conventions gave these packages a veneer of legitimacy — worth discussing what a concrete dependency-review rule looks like for a small SEA team shipping WhatsApp bots, given that the payload here is a live authenticated session rather than a stolen credential.