NEWS

101 Malicious npm Packages Hijack Developer WhatsApp Accounts via Baileys Library

OX Security found 101 npm packages abusing the Baileys WhatsApp library to silently enroll developers in scam channels, racking up 490,000 downloads.

Dylan H.

News Desk

September 29, 2026
7 min read
101 Malicious npm Packages Hijack Developer WhatsApp Accounts via Baileys Library

101 Malicious npm Packages Silently Subscribe Developer WhatsApp Accounts to Scam Channels

Researchers at OX Security have uncovered a sprawling npm supply chain campaign, dubbed "PhantomSub," built around 101 malicious packages that abuse the popular open source Baileys WhatsApp API library to add developers' WhatsApp accounts to attacker-controlled groups and channels without their consent. The malicious packages, disclosed on September 29, 2026, have collectively been downloaded roughly 490,000 times, including 116,000 downloads in the last 30 days, and the campaign is still actively growing.


Incident Details

AttributeValue
Campaign namePhantomSub
Malicious packages identified101
Total downloads~490,000 (116,000 in the last 30 days)
npm packages removed16 (as of September 28, 2026)
Abused libraryBaileys (unofficial WhatsApp Web API implementation)
Discovered byOX Security (Nir Zadok, Moshe Siman Tov Bustan, Vitalii Chepurko)
Prior related researchSafeDep (August 2026), Xygeni Security Research Team
Primary monetizationFollower/subscriber inflation for Indonesian bot-seller and gaming-account marketplace channels
Disclosure dateSeptember 29, 2026

How It Worked

Trojanized Baileys forks

Baileys is a legitimate, widely used open source library that provides an unofficial implementation of the WhatsApp Web API, letting developers build customer support bots, chat automation, and data-scraping tools by authenticating a real WhatsApp account through it. The threat actors behind PhantomSub published dozens of forked or renamed copies of Baileys — package names identified by OX Security include ourin-baileys, @nexustechpro/baileys, @badzz88/baileys, levvleys, neuralwhatsapp, kurobails, cantarella-baileys, yonzofficial, noxleyss, jexkcode, @kanaraa/baileys, spencer-baileys, and @fadzzzslebew/baileys, among roughly 90 others. The three most-downloaded packages alone — ourin-baileys (130,589 downloads), @nexustechpro/baileys (62,155 downloads), and @badzz88/baileys (52,173 downloads) — accounted for a large share of total install volume.

Three variants of the same trick

OX Security grouped the packages into three technical variants based on how they conceal the WhatsApp channel identifiers they target:

  • Variant 1 — remote fetch (19 packages): Channel IDs are pulled at runtime from GitHub-hosted JSON files, letting the operators swap targets on the fly without shipping a new npm version. cantarella-baileys, for example, fetches its channel list from a GitHub-hosted idChannel.json file.
  • Variant 2 — hardcoded cleartext (60 packages): Channel IDs are embedded directly and readably in the package source, as seen in files such as jexkcode's auto-follow.js and @kanaraa/baileys's messages-recv.js.
  • Variant 3 — encoded/obfuscated (14 packages): Channel IDs are Base64-encoded and hardcoded, as in spencer-baileys's newsletter.js.

Seven additional packages were pulled from npm before researchers could classify them into one of the three buckets.

Silent subscription and muting

Once a developer installs one of the trojanized packages and authenticates their real WhatsApp account through it — the normal setup step for any Baileys-based bot — the malicious code automatically follows or joins the attacker-designated channels and groups, in some cases after a built-in delay (researchers observed waits of roughly 90 seconds) to avoid triggering immediate suspicion. The subscription logic also mutes the added channel, so the victim's WhatsApp app does not surface notifications that would otherwise reveal the unauthorized addition.

The payoff: manufactured social proof

The channels identified by OX Security are overwhelmingly small, Indonesian-language "market" and bot-seller channels advertising gaming account sales (including TikTok and Mobile Legends: Bang Bang accounts), bot-building scripts, "premium" cracked APKs, and social-media boosting services. Inflated follower and subscriber counts function as social proof to make these storefronts look more credible to potential buyers. Shared channel IDs, common GitHub infrastructure, and near-identical package-naming templates across the set point to coordinated or overlapping operators rather than isolated copycats. One associated WhatsApp account operator was identified in the channel infrastructure only by the alias "Dan," based in Indonesia.

Part of a wider pattern of Baileys abuse

PhantomSub is not the first abuse of Baileys forks reported in 2026. In August 2026, SafeDep disclosed a separate set of malicious Baileys forks that silently made installers' WhatsApp accounts follow attacker channels and injected the author's advertising links into every image and video the bot sent. Earlier in September, the Xygeni Security Research Team detailed a Baileys mod called @dappaoffc/baileys-mod that similarly subscribed a developer's authenticated bot session to attacker-controlled newsletter channels. A related but distinct threat, a package called "lotusbail," cloned the legitimate @whiskeysockets/baileys library and inserted more advanced malware built to exfiltrate sensitive user data — a credential/data-theft scheme rather than the group-subscription scam seen in PhantomSub.

Impact Assessment

Impact AreaDescription
Account integrityDevelopers' real, authenticated WhatsApp accounts are silently enrolled in unwanted groups/channels, with notifications suppressed via muting
Reputational riskVictim accounts inflate follower counts for scam marketplaces, indirectly lending credibility to fraudulent gaming-account and APK sales
Detection difficultyRemote GitHub-hosted channel lists and encoded identifiers let operators rotate targets without new npm releases, evading static package review
Ecosystem trustNear-identical forks of a legitimate, widely trusted open source project (Baileys) make it harder for developers to distinguish safe packages from trojanized copies
Remediation lagOnly 16 of 101 identified packages had been removed from npm as of September 28, 2026; new variants continue to appear

Recommendations

For developers using Baileys or similar WhatsApp automation libraries

  • Use only the official @whiskeysockets/baileys package (the maintained upstream project), and verify the publisher, repository link, and download history before installing any fork or rebranded variant.
  • Treat any package that requests authentication of a personal or business WhatsApp account with heightened scrutiny — review its source code for outbound network calls, hidden channel/group IDs, or Base64-encoded strings before running it.
  • Audit package.json and lockfiles for Baileys-named dependencies that are not the official package, especially recently added or low-reputation scoped packages.

For security and platform teams

  • Add detection rules and allowlists that flag Baileys forks and typosquat-style names (e.g., unfamiliar -baileys suffixes or prefixes) in dependency scanning and SCA tooling.
  • Monitor outbound requests from WhatsApp-automation workloads to unexpected GitHub-hosted JSON or config endpoints, which may indicate remote-fetch-style abuse like Variant 1 above.
  • Flag and quarantine any dependency update that introduces new WhatsApp channel-join, follow, or subscription logic without a corresponding, documented feature change.

For affected users

  • If your WhatsApp account was added to an unfamiliar group or channel, especially one advertising gaming accounts, bot scripts, or "premium" APKs, report and block the group immediately.
  • Do not purchase accounts, scripts, or boosted followers from channels encountered this way — sellers in this ecosystem have a documented pattern of taking payment without delivering goods.
  • Review your WhatsApp linked-device and group membership list periodically if you run any Baileys-based automation, and remove unfamiliar memberships even after uninstalling the offending package.

Key Takeaways

  1. 101 npm packages in the PhantomSub campaign abused the Baileys WhatsApp library to silently add developers' real WhatsApp accounts to scam groups and channels, with roughly 490,000 total downloads.
  2. The packages used three technical approaches — remote GitHub-hosted channel lists, hardcoded cleartext IDs, and Base64-obfuscated IDs — to conceal which channels victims were being subscribed to.
  3. Malicious code muted the added channels to suppress notifications, and in some cases delayed execution by around 90 seconds to reduce the chance of immediate detection.
  4. The scheme monetizes inflated follower counts for Indonesian-focused marketplaces selling gaming accounts, bot scripts, premium APKs, and social-media boosting services.
  5. Only 16 of the 101 identified packages had been removed from npm as of September 28, 2026; the campaign continues to publish new variants.
  6. PhantomSub follows a pattern of Baileys-fork abuse also reported by SafeDep and the Xygeni Security Research Team in 2026, distinct from the more severe data-stealing "lotusbail" clone of @whiskeysockets/baileys.

Sources