Back to Newsroom
Threat Intel

101 Malicious npm Packages Secretly Enroll Developers in WhatsApp Bot Networks

A campaign dubbed PhantomSub uses fake 'Baileys' WhatsApp library forks to hijack developers' authenticated WhatsApp sessions and subscribe them to attacker-controlled marketing channels — without consent.

101 Malicious npm Packages Secretly Enroll Developers in WhatsApp Bot Networks

101 Malicious npm Packages Secretly Enroll Developers in WhatsApp Bot Networks

Security researchers have uncovered a sprawling supply-chain campaign — tracked as PhantomSub — built around 101 npm packages that impersonate Baileys, the popular open-source WhatsApp Web API library for Node.js. Instead of adding chat automation to a project, these packages quietly hijack the developer's own authenticated WhatsApp session.

What happened

The malicious packages, most of them typosquats or "helper" forks of Baileys (names like ourin-baileys, neuralwhatsapp, cloud-baileys and dozens of similar variants), have been downloaded roughly 490,000 times combined, with 116,000 of those installs in the past 30 days alone. Once installed, the code abuses the victim's own WhatsApp account to auto-join it — without any consent — to attacker-controlled marketing groups and "follow" channels.

Analysts identified three separate implementation patterns among the packages:

  • One set (19 packages) pulls the target channel IDs from a GitHub repository at runtime.
  • A second, larger set (60 packages) hardcodes the channel IDs directly in cleartext.
  • A third set (14 packages) embeds the same IDs but encodes or obfuscates them.

Despite different package names and publishers, many of the channel IDs, remote lists and GitHub accounts overlap — pointing to a shared operator (or a small group of operators) harvesting followers across every package variant, regardless of who nominally maintains it.

The activity traces back to at least August 2026, when a related discovery showed malicious Baileys forks stealthily hijacking a victim's "follow" channels and injecting the operator's promotional links into every image and video the bot handled. A separate, more recent disclosure found another Baileys-based package subscribing developers' authenticated sessions to attacker-run newsletter channels. Several of the identified groups target mobile-gaming and in-game-currency marketplaces, and use inflated follower counts as social proof to sell bot scripts, "boosting" services and pirated APKs.

Why it matters

This isn't a data-stealing backdoor in the traditional sense — but it is a real trust and reputational hijack. A developer who installs one of these packages effectively lends their own WhatsApp identity and follower network to someone else's marketing operation, with no visibility or control over what that operation promotes. For an organization, a compromised developer account tied to WhatsApp Business or Web sessions can also become a foothold for further social-engineering or phishing campaigns run "from" a trusted contact.

It's also a textbook case of npm typosquatting at scale: dozens of near-identical package names riding on the popularity of a legitimate, widely used library, with automated CI/CD pipelines just as capable of pulling in a poisoned package as a human npm install.

What to do

  • Search your dependency tree (package.json, lockfiles, and any transitive dependencies) for Baileys forks and typosquats rather than the official upstream package.
  • If any WhatsApp account used for development or automation may have installed one of these packages, check its group and channel memberships and leave any unrecognized groups or channels.
  • Add detection rules in your SCA/dependency-scanning pipeline to flag Baileys-named packages that aren't the verified upstream project.
  • Avoid using any Node.js package that requires linking a personal or business WhatsApp session unless its provenance and maintainers are verified.
  • Treat this as a reminder to pin dependencies, review install scripts, and monitor for typosquat variants of any library your team relies on heavily.
SHARE