⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent

September 29, 2026

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent Ravie LakshmananSep 29, 2026Supply Chain / Malware Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday. These packages have been collectively downloaded 490,000 times, out of which 116,000 occurred in the last 30 days. The names of some of the packages are below – ourin-baileys @nexustechpro/baileys @badzz88/baileys @ostyado/baileys levvleys @vanzxy/baileys @yudzxml/baileys @chatunity/baileys @kelvdra/baileys neuralwhatsapp lilys-baileys…