News / Cybersecurity
PhantomSub Campaign: 101 npm Packages Hijack Developers' WhatsApp Accounts Without Consent Published on 29 September 2026 by Christ-loisele (3 min read)
A malicious campaign targeting developers via npm exploits the Baileys library to add their WhatsApp accounts to Indonesian groups without their consent. The packages, downloaded 490,000 times, use three malware variants to bypass detection.
Targeted Exploitation of WhatsApp Libraries
Cybersecurity researchers revealed in September 2026 the existence of the PhantomSub campaign, involving 101 malicious npm packages. These impersonate legitimate forks of Baileys , an open-source library enabling automation of WhatsApp interactions via its API. According to The Hacker News , these packages were collectively downloaded 490,000 times , including 116,000 times in the last 30 days before detection.
Their mechanism relies on exploiting authenticated WhatsApp sessions of developers. Upon installation, the packages modify Baileys' behavior to automatically subscribe victims' accounts to attacker-controlled groups or channels without explicit consent. Aviatrix.ai notes that the packages use three technical variants: dynamic retrieval of channel IDs via GitHub, integration of plaintext IDs, or encoding/obfuscation of code to evade detection.
The malicious packages exploit developers' trust by mimicking legitimate Baileys forks, turning their WhatsApp accounts into monetization tools without consent.
Logo: WhatsApp (Public domain)
Indonesian Groups at the Heart of Monetization
The WhatsApp channels targeted by these packages are primarily based in Indonesia and serve as platforms for selling bots, mobile game scripts like Mobile Legends: Bang Bang , or TikTok promotion services. OX Security highlights that these groups act as « follower farms, » where follower counts serve as social proof to attract new customers. Among the identified groups are Neural (798 subscribers), CORTANA TECH (1,300 subscribers), and Fyxzpedia.ID - Utama (4,800 subscribers), all linked to bot sales or automated service activities.
Attackers exploit a flaw in the npm supply chain by blending into the developers' ecosystem. Undercode News reports that some packages, like @dappaoffc/baileys-mod, even retrieve target channel lists directly from GitHub repositories, allowing authors to update targets without republishing a new package version.
Logo: npm (Boboss74, Public domain)
Sophisticated Evasion Techniques
Unlike traditional malware, PhantomSub packages avoid easily detectable malicious signatures. OX Security explains that malicious code is often hidden in large files or embedded within seemingly harmless modules. For example, the spencer-baileys package waits 90 seconds before activating the subscription feature, reducing the risk of immediate detection. Additionally, only 16 of the 101 packages had been removed from npm by September 28, 2026, despite their danger.
Researchers highlight that attackers coordinate their actions: 32 channels are tracked by multiple packages, suggesting a centralized organization. The Hacker News adds that the packages often share the same channel identifiers and GitHub accounts, confirming a single beneficiary behind these campaigns.
What this changes here
For businesses and government agencies in Benin and West Africa, this campaign illustrates the growing risks associated with the use of third-party libraries in development projects. Technical teams could be exposed if they integrate unverified npm packages, especially for applications requiring access to personal accounts like WhatsApp or other social platforms. Local developers should systematically audit project dependencies, particularly those related to instant messaging automation, and prioritize official sources or community-maintained forks.
Public administrations, often prime targets for cyberattacks, could strengthen their security protocols by enforcing rigorous code reviews for external packages. Supply chain attacks, such as PhantomSub, demonstrate that threats are not limited to critical software: seemingly innocuous libraries can serve as vectors for spam, espionage, or botnet recruitment campaigns, as observed here with Indonesian groups.
Finally, this case underscores the importance of collective vigilance within the open-source ecosystem. African stakeholders, often reliant on international resources, should actively participate in reporting suspicious packages through platforms like GitHub Security or npm’s @npmcli/ci, to limit the spread of such campaigns on the continent.
Sources