Full Report
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical
Analysis Summary
# Tool/Technique: PhantomSub (Malicious npm Packages)
## Overview
PhantomSub is a malicious supply chain campaign targeting developers through a cluster of malicious npm packages. These packages abuse and fork the "Baileys" WhatsApp open-source library to compromise the installer's authenticated WhatsApp sessions. The primary purpose of this campaign is to forcibly subscribe victims' accounts to attacker-controlled WhatsApp groups and channels without consent, creating an artificial follower base to provide "social proof" for marketing and boosting services.
## Technical Details
- **Type:** Supply Chain Malware / Malicious Package Forks
- **Platform:** Cross-platform (Node.js / npm ecosystem)
- **Capabilities:** Unauthorized channel subscription, dynamic configuration fetching, ad injection into media files, and code obfuscation.
- **First Seen:** August 2026
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1195.002 - Supply Chain Compromise: Malicious Software Dependency
- **TA0002 - Execution**
- T1059 - Command and Scripting Interpreter (Node.js execution environment)
- **TA0011 - Command and Control**
- T1102 - Web Service (Using GitHub to host and retrieve dynamic channel lists)
## Functionality
### Core Capabilities
- **Unauthorized Group Subscription:** Automatically and stealthily forces the developer's authenticated WhatsApp bot session to follow specific groups, channels, or newsletter channels controlled by the threat actor.
- **Ad Injection:** Injects the author's advertising URLs into every image and video transmitted by the compromised WhatsApp bot.
### Advanced Features
The campaign utilizes three distinct variants to execute and manage its subscription routines:
- **Variant 1 (Dynamic Fetching):** Fetches target channel IDs dynamically from GitHub repositories at runtime to evade static detection.
- **Variant 2 (Cleartext Embedding):** Directly embeds the target channel IDs within the package source code in plaintext.
- **Variant 3 (Obfuscation):** Statically embeds target channel IDs within the source code using encoded and obfuscated formats to bypass automated code analysis tools.
## Indicators of Compromise
### File Hashes
*None provided in the source text.*
### File Names (Malicious npm Packages)
- `ourin-baileys`
- `@nexustechpro/baileys`
- `@badzz88/baileys`
- `@ostyado/baileys`
- `levvleys`
- `@vanzxy/baileys`
- `@yudzxml/baileys`
- `@chatunity/baileys`
- `@kelvdra/baileys`
- `neuralwhatsapp`
- `lilys-baileys`
- `@fyxzpediaa/baileys`
- `noxleyss`
- `@xrelly-stack/bails`
- `alipclutch-baileys`
- `kurobails`
- `eliteprotech-baileys`
- `@xayz/baileys`
- `chromestaff-baileys`
- `@sanzoffc/baileys`
- `@sairidev/baileys-new`
- `cloud-baileys`
- `@nyzzpediaa/baileys-new`
- `ishumdz-bail`
- `nishiki-bail`
- `diezyclutch-baileys`
- `oktz-baileys`
- `my-auto-follow`
- `@dappaoffc/baileys-mod`
### Registry Keys
*Not applicable.*
### Network Indicators
- `github[.]com` (Used by Variant 1 to fetch remote channel lists at runtime)
### Behavioral Indicators
- Node.js applications initiating unexpected outbound connections to GitHub during execution or installation phases.
- Automated generation of unauthorized channel join requests within WhatsApp bot sessions.
- Unprompted modification of outbound image/video metadata to append external advertising URLs.
## Associated Threat Actors
The exact identities of the actors are unknown, but evidence points to Indonesian-based threat actors or "bot-sellers." The campaign benefits specific Indonesian commercial channels/marketplaces, including:
- An Indonesian business WhatsApp account named **"Dan"** (advertises mobile game/app accounts like Mobile Legends: Bang Bang and TikTok).
- **Neural / JualanRSS** (an online marketplace selling in-game resources).
- **MONTE – BMG**
- **CORTANA TECH**
- **Fyxzpedia.ID – Utama**
## Detection Methods
- **Signature-Based Detection:** Implement blocking rules within software composition analysis (SCA) tools and package managers for the specific package names, scopes, and known malicious versions listed above.
- **Behavioral Detection:** Monitor Node.js application execution environments for unusual API interaction patterns with the WhatsApp Web/Baileys framework, specifically tracking unauthorized channel subscription methods or unexpected runtime connections to GitHub.
## Mitigation Strategies
- **Dependency Auditing:** Inspect open-source projects for the presence of unofficial or typosquatted forks of the "Baileys" WhatsApp project.
- **Access Control:** Refrain from using third-party npm packages that mandate or request access tokens/authentication for personal or sensitive corporate WhatsApp accounts.
- **Incident Response:** If infected, developers should manually inspect their WhatsApp account configurations, identify unauthorized channel or group subscriptions, block them, and revoke compromised session tokens.
## Related Tools/Techniques
- **Baileys Open-Source Project:** The legitimate WhatsApp API library targeted and modified for this campaign.
- **Typosquatting/Malicious Package Modding:** A supply chain technique involving the republication of legitimate libraries embedded with malicious post-install or runtime routines.