PhantomSub Campaign Uses 101 Malicious npm Packages to Add Developers to WhatsApp Groups

Cybersecurity researchers have identified a cluster of 101 malicious npm packages that secretly enroll developers into attacker-controlled WhatsApp groups and channels as part of a campaign dubbed PhantomSub.

The packages abuse the open-source Baileys WhatsApp library to add users to WhatsApp groups without their consent.

According to OX Security, the packages have been downloaded approximately 490,000 times, including around 116,000 downloads during the last 30 days.

Malicious Baileys Packages

Researchers identified numerous malicious packages, including:

  • ourin-baileys
  • @nexustechpro/baileys
  • @badzz88/baileys
  • @ostyado/baileys
  • levvleys
  • @vanzxy/baileys
  • @yudzxml/baileys
  • @chatunity/baileys
  • @kelvdra/baileys
  • neuralwhatsapp
  • lilys-baileys
  • @fyxzpediaa/baileys
  • noxleyss
  • @xrelly-stack/bails
  • alipclutch-baileys
  • kurobails
  • eliteprotech-baileys
  • @xayz/baileys
  • chromestaff-baileys
  • @sanzoffc/baileys
  • @sairidev/baileys-new
  • cloud-baileys
  • @nyzzpediaa/baileys-new
  • ishumdz-bail
  • nishiki-bail
  • diezyclutch-baileys
  • oktz-baileys
  • my-auto-follow

How PhantomSub Works

The campaign targets developers who use Baileys-based WhatsApp automation packages.

When one of the malicious packages is used, the code can abuse the authenticated WhatsApp session associated with the application to subscribe the account to attacker-controlled groups or channels.

This turns the developer's WhatsApp account into an unwilling subscriber and helps the operators increase the follower counts of their channels.

Researchers found that the campaign uses several different implementations of the subscription mechanism.

Three Malware Variants Identified

OX Security identified three variants among the 101 packages.

Variant 1

19 packages belong to this variant.

The packages retrieve WhatsApp channel IDs from GitHub at runtime before performing the subscription activity.

Variant 2

60 packages contain channel IDs directly within their source code in cleartext.

Variant 3

14 packages contain channel IDs in encoded and obfuscated form.

Despite the different implementations, researchers found significant infrastructure and channel overlap between packages published under different names and accounts.

WhatsApp Channels Used for Promotion

One of the identified groups appears to be associated with Indonesia and promotes accounts for mobile games and applications, including Mobile Legends: Bang Bang and TikTok.

The group also advertises an Indonesian business WhatsApp account using the name Dan.

Other channels identified during the investigation include:

  • Neural with 798 followers
  • MONTE - BMG with 1,000 followers
  • CORTANA TECH with 1,300 followers
  • Fyxzpedia.ID - Utama with 4,800 followers

Researchers said many of the channels appear to be associated with Indonesian bot sellers and online markets.

The channels reportedly promote services and products such as:

  • Bot scripts
  • Bot development services
  • Premium APKs
  • Social-media boosting
  • In-game resources

Shared Channel IDs Reveal Common Beneficiaries

Researchers found that many of the malicious packages are not independent campaigns.

The same channel IDs, remote channel lists, and GitHub accounts appear across packages with different names and publishers.

This means multiple malicious packages can direct victims toward the same WhatsApp channels.

According to researchers, the shared channel infrastructure indicates that whoever controls those channels can benefit from followers generated through multiple malicious packages.

Earlier Baileys Abuse

The PhantomSub campaign follows earlier reports involving malicious modifications of the Baileys project.

In August 2026, researchers identified Baileys npm forks that could secretly make an authenticated WhatsApp account follow channels controlled by package authors.

Some versions also injected advertising URLs into images and videos sent through the WhatsApp bot.

Earlier this month, another modified Baileys package, @dappaoffc/baileys-mod, was found subscribing authenticated WhatsApp bot sessions to attacker-controlled newsletter channels.

Developers using Baileys or related WhatsApp automation packages should:

  • Check whether their WhatsApp accounts have been unexpectedly added to groups or channels.
  • Leave and block suspicious groups and channels.
  • Review npm dependencies for malicious Baileys forks.
  • Add detection rules to prevent installation of known malicious packages.
  • Review package publishers and source repositories before installing modified Baileys packages.
  • Avoid packages that require connecting a personal WhatsApp account when such access is not necessary.
  • Review authenticated WhatsApp sessions for unexpected activity.

Key Takeaway

The PhantomSub campaign demonstrates how malicious npm packages can abuse legitimate automation libraries for purposes beyond traditional malware delivery.

Instead of directly stealing credentials, the 101 identified packages misuse authenticated WhatsApp sessions to artificially grow attacker-controlled groups and channels.

Developers should treat unofficial forks of widely used libraries with caution and carefully review package behavior before connecting applications to personal or business messaging accounts.