Researchers at OX Security have uncovered a campaign called PhantomSub involving 101 malicious npm packages that together have been downloaded about 490,000 times. The packages abuse Baileys, an open-source WhatsApp library, to add developers' WhatsApp accounts to groups without consent. Of those downloads, 116,000 occurred in the last 30 days, indicating active distribution.

According to OX Security, the packages fall into three variants. One fetches channel IDs from GitHub at runtime, another embeds channel IDs in cleartext, and a third uses obfuscated embedded IDs. Earlier findings from SafeDep and Xygeni had already flagged malicious Baileys forks that force followers and inject advertising URLs, and OX's analysis expands the scope.

The targeted groups and channels appear to be mostly Indonesian operations that use follower counts as social proof for selling bot scripts, building services, premium APKs, and social-media boosting. One identified channel markets in-game resources such as food, ore, and gold. Developers are advised to block the groups, remove suspicious packages, and avoid linking personal WhatsApp accounts to untrusted npm packages.