{"id":3238,"date":"2026-09-29T16:30:33","date_gmt":"2026-09-29T16:30:33","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3238"},"modified":"2026-09-29T16:30:33","modified_gmt":"2026-09-29T16:30:33","slug":"101-malicious-npm-packages-add-developers-whatsapp-accounts-to-groups-without-consent","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3238","title":{"rendered":"101 Malicious npm Packages Add Developers&#8217; WhatsApp Accounts to Groups Without Consent"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 29, 2026<\/span><\/span><span class=\"p-tags\">Supply Chain \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhhUmW5o4XCEsBlPE2MKecTG-IHCrk1WHeLajiNnRTpGtT-DDhpYVID3Pon7cseFiJN24GulDnjR7TPRe6h-kQEuJBPRl87atgBytMvKbiRV4h_DHWtxQEtogyy3U-aAD6ErNCrYiOQV-tHvHcw_P4W8z37PpR-jo70sePvtLIvMwKx7MJuE8Fazhyphenhyphen7_KI5\/s1700-nu-rw-lo-l85-e365\/npm-whatsapp.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed <strong>PhantomSub<\/strong>.<\/p>\n<p>\u00abThe malicious packages abuse the &#8216;Baileys&#8217; WhatsApp open source project to add the victims to groups without their consent,\u00bb OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko <a href=\"https:\/\/www.ox.security\/blog\/phantomsub-malicious-npm-campaign-secretly-adds-users-to-whatsapp-spam-channels\/\" target=\"_blank\">said<\/a> in a technical write-up published Monday.<\/p>\n<p>These packages have been collectively downloaded 490,000 times, out of which 116,000 occurred in the last 30 days. The names of some of the packages are below &#8211;<\/p>\n<ul>\n<li>ourin-baileys<\/li>\n<li>@nexustechpro\/baileys<\/li>\n<li>@badzz88\/baileys<\/li>\n<li>@ostyado\/baileys<\/li>\n<li>levvleys<\/li>\n<li>@vanzxy\/baileys<\/li>\n<li>@yudzxml\/baileys<\/li>\n<li>@chatunity\/baileys<\/li>\n<li>@kelvdra\/baileys<\/li>\n<li>neuralwhatsapp<\/li>\n<li>lilys-baileys<\/li>\n<li>@fyxzpediaa\/baileys<\/li>\n<li>noxleyss<\/li>\n<li>@xrelly-stack\/bails<\/li>\n<li>alipclutch-baileys<\/li>\n<li>kurobails<\/li>\n<li>eliteprotech-baileys<\/li>\n<li>@xayz\/baileys<\/li>\n<li>chromestaff-baileys<\/li>\n<li>@sanzoffc\/baileys<\/li>\n<li>@sairidev\/baileys-new<\/li>\n<li>cloud-baileys<\/li>\n<li>@nyzzpediaa\/baileys-new<\/li>\n<li>ishumdz-bail<\/li>\n<li>nishiki-bail<\/li>\n<li>diezyclutch-baileys<\/li>\n<li>oktz-baileys<\/li>\n<li>my-auto-follow<\/li>\n<\/ul>\n<p>Details of the activity first emerged in August 2026, when SafeDep said it identified a set of Baileys npm forks that were found to engage in malicious behaviors, such as stealthily making the installer&#8217;s WhatsApp account follow channels the package author controls and injecting the author&#8217;s advertising URL into every image and video the bot sends.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Then, earlier this month, the Xygeni Security Research Team disclosed details of another Baileys mod named \u00ab<a href=\"https:\/\/xygeni.io\/blog\/malicious-npm-package-in-baileys-fork-skyzopedia-case\/\" target=\"_blank\">@dappaoffc\/baileys-mod<\/a>\u00bb that was also found to subscribe the developer&#8217;s authenticated WhatsApp bot session to attacker-controlled newsletter channels.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>OX Security&#8217;s analysis has uncovered three different variants of the malware, each implementing different ways of handling the subscription routine &#8211;<\/p>\n<ul>\n<li>Variant 1 (19 packages), which fetches channel IDs from GitHub at runtime<\/li>\n<li>Variant 2 (60 packages), which embeds channel IDs in its source code in cleartext<\/li>\n<li>Variant 3 (14 packages), which embeds channel IDs in its source code in encoded and obfuscated form<\/li>\n<\/ul>\n<p>One of the WhatsApp groups is assessed to be based in Indonesia and advertises accounts for mobile games and applications, such as Mobile Legends: Bang Bang and TikTok. These posts also specify a phone number that&#8217;s linked to an Indonesian business WhatsApp account named \u00abDan.\u00bb<\/p>\n<p>Some of the other identified groups and channels are listed below &#8211;<\/p>\n<ul>\n<li>Neural (798 followers), which markets Resource Supplies (RSS) sales using JualanRSS, an online marketplace that sells in-game resources such as food, ore, stone, timber, and gold.<\/li>\n<li>MONTE \u2013 BMG (1,000 followers)<\/li>\n<li>CORTANA TECH (1,300 followers)<\/li>\n<li>Fyxzpedia.ID \u2013 Utama (4,800 followers)<\/li>\n<\/ul>\n<p>\u00abThe channels we could identify are mostly small bot-seller and &#8216;market&#8217; channels, largely Indonesian, where follower counts serve as social proof for selling bot scripts, bot-building services, &#8216;premium&#8217; APKs and social-media boosting,\u00bb OX Security said.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/event-security-need\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJkE4t8oCql1wmWVt687J1yD7WnYRqvIpcsUwFSVUO-0HpxZWMCxLmeYwBlz38-C0KD-R6f9Pg0swgPTQuBsNXck_Kl3iKWNSQtyMcDNUSZGhiBd_XFu6U1SQi5LhuW-FHg00iT3CbRCUgMoCwhZevwxp8-9gwM2wZVVtGVO8Z2NbZ5EjVmI2dH4adnSAk\/s728-nu-rw-lo-l85-e365\/Shai-Hulud-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abMany packages in this campaign are not independent. The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers. A shared channel means a shared beneficiary: whoever owns the channel collects followers from every package that targets it, whoever published the package.\u00bb<\/p>\n<p>Developers are advised to check if they have been added to the WhatsApp groups, block them, configure detection rules for blocking the malicious npm Baileys packages, and refrain from using packages that require the personal WhatsApp account to be connected.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 29, 2026Supply Chain \/ Malware Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3239,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[592,3244,1724,149,1499,33,39,35,815],"class_list":["post-3238","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-accounts","tag-add","tag-consent","tag-developers","tag-groups","tag-malicious","tag-npm","tag-packages","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3238"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3238\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3239"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}