Cybersecurity experts have uncovered a scheme involving 101 npm packages designed to unwittingly subscribe developers to WhatsApp groups. This campaign, named PhantomSub, exploits the ‘Baileys’ WhatsApp open-source project to add users without their approval, according to researchers from OX Security.
The Scale of the Threat
The affected npm packages have collectively been downloaded nearly 490,000 times, with 116,000 downloads occurring in the past month alone. These packages, such as ‘ourin-baileys’ and ‘@nexustechpro/baileys’, are being used to carry out unauthorized group subscriptions.
The issue first came to light in August 2026 when SafeDep reported that certain Baileys npm forks were involved in malicious activities. These activities included covertly subscribing the installer’s WhatsApp account to channels managed by the package authors and embedding advertiser URLs into bot communications.
Variants and Techniques
OX Security’s analysis revealed three malware variants, each employing different subscription strategies. Variant 1, consisting of 19 packages, retrieves channel IDs from GitHub at runtime. Variant 2, with 60 packages, embeds these IDs directly in the source code. Variant 3, comprising 14 packages, uses encoded and obfuscated forms to hide channel IDs.
One prominent WhatsApp group involved, believed to be based in Indonesia, promotes accounts for mobile games and applications. Other identified channels, such as ‘Neural’ and ‘CORTANA TECH’, operate in niche markets, selling bot scripts and resources.
Security Recommendations
OX Security underscores the interconnected nature of these packages, sharing channel IDs and GitHub accounts across different names and publishers. This interconnectedness suggests a common beneficiary, collecting followers from every targeted package.
Developers are encouraged to verify if they have been added to these WhatsApp groups and take action to block them. Additionally, they should implement detection rules to identify and block the malicious npm Baileys packages and avoid using packages that require linking personal WhatsApp accounts.
Conclusion
As digital threats evolve, the importance of vigilant cybersecurity practices cannot be overstated. The discovery of these npm packages highlights the need for developers to remain cautious when integrating third-party resources. By staying informed and proactive, developers can better protect their digital environments from such sophisticated attacks.
