"The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said.
PhantomSub: a cluster of 101 npm packages
Cybersecurity researchers at OX Security have identified a campaign they call PhantomSub that uses 101 npm packages to add developers' WhatsApp accounts to groups and channels without consent. The packages collectively have been downloaded 490,000 times, with 116,000 downloads occurring in the last 30 days.
OX Security says the packages "abuse the 'Baileys' WhatsApp open source project" to implement the subscription behavior. The activity echoes earlier findings: in August 2026 SafeDep reported Baileys npm forks that stealthily made installers' WhatsApp accounts follow channels and injected an author's advertising URL into media, and the Xygeni Security Research Team disclosed a Baileys mod named "@dappaoffc/baileys-mod" that subscribed authenticated WhatsApp bot sessions to attacker-controlled newsletter channels.
OX Security published a list of many of the packages associated with PhantomSub. Examples include ourin-baileys, @nexustechpro/baileys, @badzz88/baileys, @ostyado/baileys, levvleys, @vanzxy/baileys, @yudzxml/baileys, @chatunity/baileys and neuralwhatsapp. Other named packages include @fyxzpediaa/baileys, @xrelly-stack/bails, alipclutch-baileys, eliteprotech-baileys, cloud-baileys, my-auto-follow and dozens more.
Three malware variants and their mechanics
OX Security's analysis identifies three distinct variants of the malicious code, which implement different approaches to the subscription routine:
- Variant 1 — 19 packages: fetches channel IDs from GitHub at runtime.
- Variant 2 — 60 packages: embeds channel IDs in source code in cleartext.
- Variant 3 — 14 packages: embeds channel IDs in source code in encoded and obfuscated form.
Each variant converges on the same outcome: the installer's authenticated WhatsApp session is used to follow or join channels the package author controls, effectively turning the developer's account into a follower for the attacker's channels.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTarget groups, follower markets, and an Indonesian cluster
OX Security mapped several of the groups and channels that benefit from the campaign. One assessed WhatsApp group is based in Indonesia and advertises accounts for mobile games and applications, such as Mobile Legends: Bang Bang and TikTok. That group's posts include a phone number linked to an Indonesian business WhatsApp account named "Dan."
Other identified channels and follower counts include:
- Neural — 798 followers; markets Resource Supplies (RSS) sales via JualanRSS, selling in-game resources such as food, ore, stone, timber, and gold.
- MONTE – BMG — 1,000 followers.
- CORTANA TECH — 1,300 followers.
- Fyxzpedia.ID – Utama — 4,800 followers.
OX Security characterized the channels they could identify as "mostly small bot-seller and 'market' channels, largely Indonesian, where follower counts serve as social proof for selling bot scripts, bot-building services, 'premium' APKs and social-media boosting."
Crucially, OX Security observed that many packages are not independent: "The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers. A shared channel means a shared beneficiary: whoever owns the channel collects followers from every package that targets it, whoever published the package."
Developer guidance and technical mitigations
OX Security advised developers to take several concrete steps if they suspect they have been affected:
- Check whether your WhatsApp account has been added to the named groups and block them.
- Configure detection rules for blocking the malicious npm Baileys packages.
- Refrain from using packages that require the personal WhatsApp account to be connected.
The researchers framed these actions as practical ways to interrupt the campaign’s ability to recruit followers from unsuspecting developers' authenticated sessions.
How technologists, procurement leaders, and end users should respond
Technologists and security teams should prioritize detection rules that target the specific Baileys forks and monitor installations that request WhatsApp account connections, since many packages embed or fetch the same channel IDs across different publishers.
Procurement leaders and repository managers should treat packages that require a personal WhatsApp account as a red flag and enforce policies that disallow such dependencies in production or developer machines.
Developers and end users should inspect recent package installs, verify whether their WhatsApp account appears in any of the groups listed, and block or leave groups as recommended by OX Security.
The PhantomSub campaign ties a sizable npm download footprint to a persistent social-engineering outcome: followers and perceived social proof for small bot-seller markets. OX Security's findings link 101 packages, shared channel identifiers, and at least several explicitly named groups and channels — leaving a clear, immediate task for developers and defenders to identify and neutralize the affected Baileys forks.




