A cluster of 101 malicious npm packages has been identified as part of a WhatsApp group subscriber campaign dubbed PhantomSub. The packages abuse the Baileys open‑source WhatsApp library to secretly add victims to groups controlled by the package authors. The campaign has amassed around 490,000 downloads, with about 116,000 of those in the last 30 days.
Examples of the offending packages include ourin-baileys, @nexustechpro/baileys, @badzz88/baileys, neuralwhatsapp, and several others that use variations of “baileys” in their names. The activity first emerged in August 2026 when SafeDep flagged Baileys forks behaving maliciously, and more details were later shared by Xygeni Security and OX Security.
OX Security’s investigation reveals three variants of the malware’s subscription mechanism. Variant 1 (19 packages) fetches channel IDs from GitHub at runtime; Variant 2 (60 packages) embeds channel IDs in cleartext within the source code; Variant 3 (14 packages) stores channel IDs in encoded/obfuscated form. One of the WhatsApp groups appears to be Indonesia‑based and advertises bot services for mobile games and apps, with posts linked to an Indonesian business WhatsApp account.
The attackers’ channels tend to be small bot‑seller and market groups, many with modest follower counts, and a common pattern shows the same channel IDs and lists reused across multiple packages and publishers. Practical responses recommended include checking whether one has been added to any such groups, blocking those accounts, and applying detection rules to block the malicious npm Baileys packages, while avoiding packages that require connecting a personal WhatsApp account.