Researchers identified PhantomSub, a coordinated npm supply-chain campaign in which 101 malicious packages abuse forks of Baileys, an unofficial WhatsApp API library. When developers authenticate WhatsApp through affected packages, the code silently subscribes their accounts to attacker-controlled groups or channels, sometimes muting them to avoid detection. The packages have accumulated about 490,000 downloads, including 116,000 in the prior 30 days, and many remained available as of September 28.
The packages retrieve target channel identifiers from GitHub-hosted lists or conceal them as plaintext, Base64-encoded, or otherwise obfuscated values. The operation appears designed to manufacture follower counts and social proof for channels promoting bot scripts, premium APKs, gaming resources, social-media boosting, and account sales, largely within an Indonesian-focused ecosystem. Shared channel IDs, GitHub infrastructure, and nearly identical package names indicate coordinated or overlapping operators; removals have not ended the threat because new variants continue to be published.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Xygeni Security Research Team disclosed that @dappaoffc/baileys-mod subscribed an authenticated WhatsApp bot session to attacker-controlled newsletter channels.
SafeDep reported that malicious npm forks of the Baileys WhatsApp library caused installers' WhatsApp accounts to follow attacker-controlled channels. It also found some forks inserted an author's advertising URL into bot-sent images and videos.
Researchers identified PhantomSub, a coordinated campaign comprising 101 malicious npm packages derived from or associated with the Baileys ecosystem. The packages silently add authenticated victim WhatsApp accounts to attacker-controlled groups or channels, with shared identifiers and infrastructure indicating overlapping operators or beneficiaries.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.