Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-1 of 1 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 29 Sep 2026, 9:45 PM | The Hacker News | 7.0 | 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
OX Security researchers identified 101 npm packages that abuse the open-source 'Baileys' WhatsApp library to silently add victims' WhatsApp accounts to attacker-controlled groups and channels, a campaign dubbed PhantomSub. The packages have been downloaded 490,000 times in total, with 116,000 of those downloads in the last 30 days, and split into three variants: 19 fetch channel IDs from GitHub at runtime, 60 hardcode them in cleartext, and 14 embed them encoded/obfuscated. The write-up follows earlier August 2026 SafeDep findings on malicious Baileys forks and a September Xygeni disclosure about '@dappaoffc/baileys-mod'; one of the groups is assessed to be based in Indonesia and advertises mobile-game and app accounts including Mobile Legends: Bang Bang and TikTok. Why: If you build or self-host a WhatsApp bot, the practical risk is not just a bad dependency: an already-authenticated Baileys session can be made to follow or join channels, and SafeDep's earlier finding also showed ad URLs being injected into every image and video the bot sends. Check your lockfile for any Baileys fork under a random scope or a name like 'ourin-baileys', 'noxleyss', or '@nexustechpro/baileys', and if one is present, remove it, rotate/re-link the WhatsApp session, and re-audit anything the bot posted. The 116,000 downloads in the last 30 days means these packages are still live and being pulled now, so this is a today check, not a backlog item. |