Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Packages Trap Developers in WhatsApp Groups

Malicious npm Packages Trap Developers in WhatsApp Groups

Posted on September 29, 2026 By CWS

Cybersecurity experts have uncovered a scheme involving 101 npm packages designed to unwittingly subscribe developers to WhatsApp groups. This campaign, named PhantomSub, exploits the ‘Baileys’ WhatsApp open-source project to add users without their approval, according to researchers from OX Security.

The Scale of the Threat

The affected npm packages have collectively been downloaded nearly 490,000 times, with 116,000 downloads occurring in the past month alone. These packages, such as ‘ourin-baileys’ and ‘@nexustechpro/baileys’, are being used to carry out unauthorized group subscriptions.

The issue first came to light in August 2026 when SafeDep reported that certain Baileys npm forks were involved in malicious activities. These activities included covertly subscribing the installer’s WhatsApp account to channels managed by the package authors and embedding advertiser URLs into bot communications.

Variants and Techniques

OX Security’s analysis revealed three malware variants, each employing different subscription strategies. Variant 1, consisting of 19 packages, retrieves channel IDs from GitHub at runtime. Variant 2, with 60 packages, embeds these IDs directly in the source code. Variant 3, comprising 14 packages, uses encoded and obfuscated forms to hide channel IDs.

One prominent WhatsApp group involved, believed to be based in Indonesia, promotes accounts for mobile games and applications. Other identified channels, such as ‘Neural’ and ‘CORTANA TECH’, operate in niche markets, selling bot scripts and resources.

Security Recommendations

OX Security underscores the interconnected nature of these packages, sharing channel IDs and GitHub accounts across different names and publishers. This interconnectedness suggests a common beneficiary, collecting followers from every targeted package.

Developers are encouraged to verify if they have been added to these WhatsApp groups and take action to block them. Additionally, they should implement detection rules to identify and block the malicious npm Baileys packages and avoid using packages that require linking personal WhatsApp accounts.

Conclusion

As digital threats evolve, the importance of vigilant cybersecurity practices cannot be overstated. The discovery of these npm packages highlights the need for developers to remain cautious when integrating third-party resources. By staying informed and proactive, developers can better protect their digital environments from such sophisticated attacks.

The Hacker News Tags:Baileys, Cybersecurity, developer security, Malware, npm packages, Open Source, OX Security, PhantomSub, supply chain attack, WhatsApp

Post navigation

Previous Post: Silver Fox Hackers Exploit Fake Software Sites for Malware
Next Post: DARPA Enlists Xint for AI-Enhanced Military App Security

Related Posts

Trojanized Gaming Tools Spread Java RAT via Online Platforms Trojanized Gaming Tools Spread Java RAT via Online Platforms The Hacker News
OpenAI Agents Implicated in RubyGems Attack OpenAI Agents Implicated in RubyGems Attack The Hacker News
AI’s Role in Evolving Cybersecurity Validation AI’s Role in Evolving Cybersecurity Validation The Hacker News
Preparing for Quantum Security: A Crucial Webinar Preparing for Quantum Security: A Crucial Webinar The Hacker News
China-Based APTs Deploy Fake Dalai Lama Apps to Spy on Tibetan Community China-Based APTs Deploy Fake Dalai Lama Apps to Spy on Tibetan Community The Hacker News
Global Crypto Scam Crackdown: 276 Arrests, 1M Seized Global Crypto Scam Crackdown: 276 Arrests, $701M Seized The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Enhancing Phishing Detection with Threat Intelligence
  • Preparing for Future Cyber Threats with Resilience
  • French Tax Data Breach Undetected for Weeks
  • Alleged ShinyHunters Leader Arrested by FBI and Dutch Police
  • DARPA Enlists Xint for AI-Enhanced Military App Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Enhancing Phishing Detection with Threat Intelligence
  • Preparing for Future Cyber Threats with Resilience
  • French Tax Data Breach Undetected for Weeks
  • Alleged ShinyHunters Leader Arrested by FBI and Dutch Police
  • DARPA Enlists Xint for AI-Enhanced Military App Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark