Threat Intelligence

101 Malicious npm Packages Hijack Developers' WhatsApp Accounts to Boost Fake Groups

The Hacker News · 29 Sept 2026
Key Takeaway Small businesses using developers or automation tools that integrate with WhatsApp should verify npm packages carefully and audit dependencies for unauthorised behaviour before deployment.

Security researchers at OX Security have uncovered a campaign, dubbed PhantomSub, involving 101 npm packages that abuse the open source 'Baileys' WhatsApp project. Once installed, these packages silently subscribe the developer's authenticated WhatsApp session to groups and channels controlled by the attackers, without consent. The packages have been downloaded roughly 490,000 times in total, with 116,000 of those downloads occurring in just the last 30 days.

This is not an isolated incident. Similar malicious Baileys forks were reported earlier in 2026, including versions that made victims' accounts follow attacker channels or inserted advertising links into messages sent by the bot. Researchers found that many of these packages, despite having different names and publishers, share the same channel IDs and GitHub accounts, suggesting a coordinated effort where a single group benefits from followers gained across multiple fake packages. Many of the identified channels appear linked to Indonesia-based bot-selling and app-marketing groups.

The campaign highlights how attackers exploit trust in open source developer tools to build fake social proof and follower counts for underground marketplaces selling bots, scripts and boosting services. Developers using WhatsApp automation libraries should be cautious about which packages they install and monitor for unexpected account activity.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.