Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent

The Hacker News by The Hacker News
September 29, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananSep 29, 2026Supply Chain / Malware

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.

“The malicious packages abuse the ‘Baileys’ WhatsApp open source project to add the victims to groups without their consent,” OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday.

These packages have been collectively downloaded 490,000 times, out of which 116,000 occurred in the last 30 days. The names of some of the packages are below –

  • ourin-baileys
  • @nexustechpro/baileys
  • @badzz88/baileys
  • @ostyado/baileys
  • levvleys
  • @vanzxy/baileys
  • @yudzxml/baileys
  • @chatunity/baileys
  • @kelvdra/baileys
  • neuralwhatsapp
  • lilys-baileys
  • @fyxzpediaa/baileys
  • noxleyss
  • @xrelly-stack/bails
  • alipclutch-baileys
  • kurobails
  • eliteprotech-baileys
  • @xayz/baileys
  • chromestaff-baileys
  • @sanzoffc/baileys
  • @sairidev/baileys-new
  • cloud-baileys
  • @nyzzpediaa/baileys-new
  • ishumdz-bail
  • nishiki-bail
  • diezyclutch-baileys
  • oktz-baileys
  • my-auto-follow

Details of the activity first emerged in August 2026, when SafeDep said it identified a set of Baileys npm forks that were found to engage in malicious behaviors, such as stealthily making the installer’s WhatsApp account follow channels the package author controls and injecting the author’s advertising URL into every image and video the bot sends.

Then, earlier this month, the Xygeni Security Research Team disclosed details of another Baileys mod named “@dappaoffc/baileys-mod” that was also found to subscribe the developer’s authenticated WhatsApp bot session to attacker-controlled newsletter channels.

OX Security’s analysis has uncovered three different variants of the malware, each implementing different ways of handling the subscription routine –

  • Variant 1 (19 packages), which fetches channel IDs from GitHub at runtime
  • Variant 2 (60 packages), which embeds channel IDs in its source code in cleartext
  • Variant 3 (14 packages), which embeds channel IDs in its source code in encoded and obfuscated form

One of the WhatsApp groups is assessed to be based in Indonesia and advertises accounts for mobile games and applications, such as Mobile Legends: Bang Bang and TikTok. These posts also specify a phone number that’s linked to an Indonesian business WhatsApp account named “Dan.”

Some of the other identified groups and channels are listed below –

  • Neural (798 followers), which markets Resource Supplies (RSS) sales using JualanRSS, an online marketplace that sells in-game resources such as food, ore, stone, timber, and gold.
  • MONTE – BMG (1,000 followers)
  • CORTANA TECH (1,300 followers)
  • Fyxzpedia.ID – Utama (4,800 followers)

“The channels we could identify are mostly small bot-seller and ‘market’ channels, largely Indonesian, where follower counts serve as social proof for selling bot scripts, bot-building services, ‘premium’ APKs and social-media boosting,” OX Security said.

“Many packages in this campaign are not independent. The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers. A shared channel means a shared beneficiary: whoever owns the channel collects followers from every package that targets it, whoever published the package.”

Developers are advised to check if they have been added to the WhatsApp groups, block them, configure detection rules for blocking the malicious npm Baileys packages, and refrain from using packages that require the personal WhatsApp account to be connected.



Source link

The Hacker News

The Hacker News

Next Post

Trump’s municipal bond portfolio reaches as much as $1 billion as policy overlaps mount

Recommended.

Workers fear their skills will be obsolete this decade, report finds

Workers fear their skills will be obsolete this decade, report finds

December 17, 2024
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

April 18, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio