101 Malicious npm Packages Add Developers to WhatsApp Groups

OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
Table of Contents
    Add a header to begin generating the table of contents

    OX Security researchers identified a cluster of 101 malicious npm packages that abuse the open-source Baileys WhatsApp library to add unsuspecting developers to WhatsApp groups without their consent after installation, a campaign the researchers dubbed “PhantomSub.”

    Packages Abuse the Open-Source Baileys WhatsApp Library

    Baileys is an open-source Node.js library that developers use to build applications interacting with WhatsApp. The 101 malicious packages identified in the PhantomSub campaign build on that legitimate project’s functionality, but instead of simply providing the WhatsApp integration a developer expects, they trigger an unauthorized action: adding the installing developer to a WhatsApp group without any consent or notification step.

    Researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko Published the Findings

    OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko authored the technical breakdown of the campaign. Their research documents how the 101 packages were structured to trap developers who unknowingly install one of them as a dependency, whether directly or as a transitive dependency pulled in by another package in a project’s dependency tree.

    Consent-Free WhatsApp Group Additions Distinguish This Campaign

    Unlike npm supply-chain attacks that focus on credential theft, cryptocurrency wallet draining, or remote code execution, PhantomSub’s documented effect is limited to adding the installing developer to WhatsApp groups they did not agree to join. That outcome is less immediately damaging than the credential-theft or backdoor payloads seen in many prior npm supply-chain incidents, but it still represents unauthorized access to and manipulation of the installing developer’s WhatsApp account context through code they did not knowingly authorize to take that action.

    101 Packages Published to Trap Developers Pulling in the Baileys Dependency

    The scale of the campaign, 101 distinct malicious packages, indicates a deliberate effort to seed the npm registry broadly rather than relying on a single compromised package to reach victims. Developers searching for WhatsApp integration tools, or pulling in a package that itself depends on one of the 101 flagged packages, could be affected without directly searching for or installing a package by its exact malicious name.

    Publishing 101 separate packages rather than compromising a single widely used one also gives the campaign resilience against takedown: removing any individual package, or even a substantial portion of them, would still leave the remainder available to reach new developers until the full set is identified and removed from the registry.

    npm Registry Notified as Developers Are Urged to Audit Dependencies

    OX Security published indicators and the specific package names associated with the PhantomSub campaign as part of its disclosure. npm registry maintainers have been notified for takedown of the identified packages. Developers who use the Baileys library, or who maintain projects with WhatsApp-related dependencies, are being urged to audit their dependency trees and review any WhatsApp-related packages added recently, since a transitive dependency pulled in indirectly would not necessarily appear as an obvious top-level package in a typical dependency review.

    The technical breakdown published by Zadok, Bustan, and Chepurko gives affected developers a concrete list to check their own projects against, rather than a general description of the threat pattern. Because the campaign exploited functionality within a legitimate library rather than injecting entirely separate malicious code, standard dependency-scanning tools that only flag known-bad packages by name would only catch the exposure once the specific package names from OX Security’s list are added to their detection databases.

    The campaign adds to a pattern of abuse targeting the npm registry, where attackers continue to find ways to piggyback on the reputation of legitimate open-source projects like Baileys to reach developers who trust the underlying library’s functionality. Because the 101 packages were built around a real, actively used open-source project rather than a fabricated one, developers had less reason to treat any single package name as inherently suspicious, a factor that likely extended the campaign’s reach before OX Security’s disclosure brought it to public attention.

    Related Posts