Cybersecurity researchers have uncovered a collection of 101 npm packages designed to ensnare developers in a WhatsApp group subscriber operation called PhantomSub. The packages, detailed in a technical analysis published Monday by OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko, have been downloaded 490,000 times in total, with 116,000 of those downloads occurring within the past month. The malicious code exploits the Baileys WhatsApp open source project to force victims into groups without their permission.

The researchers identified three distinct versions of the malware, each using different methods to carry out the subscription routine. The first variant, comprising 19 packages, retrieves channel IDs from GitHub while running. The second variant, representing 60 packages, hardcodes channel IDs directly into its source code as plain text. The third variant, which accounts for 14 packages, embeds channel IDs into its source code using encoded and obfuscated formats. The campaign's roots trace back to August 2026, when SafeDep first spotted Baileys npm forks engaging in harmful actions, including secretly forcing the installer's WhatsApp account to follow channels controlled by the package creator and inserting the creator's advertising URL into every image and video sent by the bot. Earlier this month, the Xygeni Security Research Team revealed another Baileys modification called "@dappaoffc/baileys-mod" that similarly enrolled the developer's authenticated WhatsApp bot session into attacker-controlled newsletter channels.

The malicious packages include names like ourin-baileys, @nexustechpro/baileys, @badzz88/baileys, @ostyado/baileys, levvleys, @vanzxy/baileys, @yudzxml/baileys, @chatunity/baileys, @kelvdra/baileys, neuralwhatsapp, lilys-baileys, @fyxzpediaa/baileys, noxleyss, @xrelly-stack/bails, alipclutch-baileys, kurobails, eliteprotech-baileys, @xayz/baileys, chromestaff-baileys, @sanzoffc/baileys, @sairidev/baileys-new, cloud-baileys, @nyzzpediaa/baileys-new, ishumdz-bail, nishiki-bail, diezyclutch-baileys, oktz-baileys, and my-auto-follow. One of the WhatsApp groups appears to originate from Indonesia and promotes accounts for mobile games and apps such as Mobile Legends: Bang Bang and TikTok, with posts listing a phone number connected to an Indonesian business WhatsApp account labeled "Dan." Other discovered groups and channels include Neural with 798 followers, which sells Resource Supplies (RSS) through JualanRSS, an online marketplace offering in-game resources like food, ore, stone, timber, and gold; MONTE – BMG with 1,000 followers; CORTANA TECH with 1,300 followers; and Fyxzpedia.ID – Utama with 4,800 followers.

"The channels we could identify are mostly small bot-seller and 'market' channels, largely Indonesian, where follower counts serve as social proof," the OX Security researchers wrote. The report notes that many packages in the campaign aren't independent, as identical channel IDs, the same remote channel lists, and the same GitHub accounts surface across packages with different names and publishers. According to the researchers, a shared channel indicates a shared beneficiary: whoever owns the channel gathers followers from every package that targets it, regardless of who published the package. The researchers explain that the operation's goal is to inflate follower counts artificially, creating the appearance of legitimacy for channels selling bot scripts, bot-building services, premium APKs, and social media boosting services primarily in Indonesian markets.

The report recommends that developers verify whether they've been added to these WhatsApp groups and block them if so, set up detection rules to prevent the malicious npm Baileys packages from being installed, and avoid using packages that require connecting a personal WhatsApp account. The campaign's scale and persistence underscore the need for vigilance when selecting open source dependencies, particularly when they request access to messaging platforms. Organizations that rely on bot frameworks for customer engagement or automation will need to weigh the convenience of third-party packages against the operational risk of unwanted subscriptions and potential brand damage. The distribution of malicious code through trusted package repositories continues to challenge conventional security models, particularly when attackers prioritize subscriber growth over more destructive payloads.