Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Packages Trap Developers in WhatsApp Groups

Malicious npm Packages Trap Developers in WhatsApp Groups

Posted on September 29, 2026 By CWS

Cybersecurity experts have uncovered a scheme involving 101 npm packages designed to unwittingly subscribe developers to WhatsApp groups. This campaign, named PhantomSub, exploits the ‘Baileys’ WhatsApp open-source project to add users without their approval, according to researchers from OX Security.

The Scale of the Threat

The affected npm packages have collectively been downloaded nearly 490,000 times, with 116,000 downloads occurring in the past month alone. These packages, such as ‘ourin-baileys’ and ‘@nexustechpro/baileys’, are being used to carry out unauthorized group subscriptions.

The issue first came to light in August 2026 when SafeDep reported that certain Baileys npm forks were involved in malicious activities. These activities included covertly subscribing the installer’s WhatsApp account to channels managed by the package authors and embedding advertiser URLs into bot communications.

Variants and Techniques

OX Security’s analysis revealed three malware variants, each employing different subscription strategies. Variant 1, consisting of 19 packages, retrieves channel IDs from GitHub at runtime. Variant 2, with 60 packages, embeds these IDs directly in the source code. Variant 3, comprising 14 packages, uses encoded and obfuscated forms to hide channel IDs.

One prominent WhatsApp group involved, believed to be based in Indonesia, promotes accounts for mobile games and applications. Other identified channels, such as ‘Neural’ and ‘CORTANA TECH’, operate in niche markets, selling bot scripts and resources.

Security Recommendations

OX Security underscores the interconnected nature of these packages, sharing channel IDs and GitHub accounts across different names and publishers. This interconnectedness suggests a common beneficiary, collecting followers from every targeted package.

Developers are encouraged to verify if they have been added to these WhatsApp groups and take action to block them. Additionally, they should implement detection rules to identify and block the malicious npm Baileys packages and avoid using packages that require linking personal WhatsApp accounts.

Conclusion

As digital threats evolve, the importance of vigilant cybersecurity practices cannot be overstated. The discovery of these npm packages highlights the need for developers to remain cautious when integrating third-party resources. By staying informed and proactive, developers can better protect their digital environments from such sophisticated attacks.

The Hacker News Tags:Baileys, Cybersecurity, developer security, Malware, npm packages, Open Source, OX Security, PhantomSub, supply chain attack, WhatsApp

Post navigation

Previous Post: Silver Fox Hackers Exploit Fake Software Sites for Malware
Next Post: DARPA Enlists Xint for AI-Enhanced Military App Security

Related Posts

Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension The Hacker News
Major Microsoft 365 Phishing Operations Exposed by Server Error Major Microsoft 365 Phishing Operations Exposed by Server Error The Hacker News
CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited The Hacker News
CISA Highlights Exploited Vulnerabilities in Key Software CISA Highlights Exploited Vulnerabilities in Key Software The Hacker News
How to Browse the Web More Sustainably With a Green Browser How to Browse the Web More Sustainably With a Green Browser The Hacker News
Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Preparing for Future Cyber Threats with Resilience
  • French Tax Data Breach Undetected for Weeks
  • Alleged ShinyHunters Leader Arrested by FBI and Dutch Police
  • DARPA Enlists Xint for AI-Enhanced Military App Security
  • Malicious npm Packages Trap Developers in WhatsApp Groups

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Preparing for Future Cyber Threats with Resilience
  • French Tax Data Breach Undetected for Weeks
  • Alleged ShinyHunters Leader Arrested by FBI and Dutch Police
  • DARPA Enlists Xint for AI-Enhanced Military App Security
  • Malicious npm Packages Trap Developers in WhatsApp Groups

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark