Ethical Hacking News
A recent discovery by cybersecurity researchers has shed light on a disturbing trend of malicious npm packages that have been found to add developers' WhatsApp accounts to groups without their consent. The affected packages, which total 101 in number, have collectively been downloaded over 490,000 times. This raises significant concerns about the security and privacy of developers' personal accounts, as well as the potential for exploitation by malicious actors. The incident highlights the need for greater awareness and vigilance among developers, as well as the importance of regular security audits and testing. Developers are advised to take immediate action to protect their personal accounts and to refrain from using packages that require access to their WhatsApp accounts.
Malicious npm packages have been found to add developers' WhatsApp accounts to groups without their consent. The affected packages have collectively been downloaded over 490,000 times. The attack has significant implications for developers using the Baileys WhatsApp open source project. The malicious packages exploit a vulnerability in the Baileys WhatsApp open source project. Developers are advised to check if they have been added to the WhatsApp groups, block them, and refrain from using packages that require access to their personal accounts.
A recent discovery by cybersecurity researchers has shed light on a disturbing trend of malicious npm packages that have been found to add developers' WhatsApp accounts to groups without their consent. The affected packages, which total 101 in number, are part of the "Baileys" WhatsApp open source project, and have collectively been downloaded over 490,000 times. This raises significant concerns about the security and privacy of developers' personal accounts, as well as the potential for exploitation by malicious actors.
The packages in question are Baileys-named npm forks that have been found to engage in malicious behaviors, such as stealthily making the installer's WhatsApp account follow channels the package author controls and injecting the author's advertising URL into every image and video the bot sends. This behavior is reminiscent of phishing scams, where attackers trick victims into divulging sensitive information. In this case, the malicious packages are tricking developers into subscribing their WhatsApp accounts to groups controlled by the attackers.
The malicious packages have been identified as variants of the "PhantomSub" campaign, which is believed to have originated from Indonesia. The campaign has been found to subscribe developers to groups that market resource supplies, mobile games, and applications, as well as other suspicious-looking channels. Some of the identified groups and channels include Neural, MONTE – BMG, CORTANA TECH, Fyxzpedia.ID – Utama, and Neural (798 followers), which markets resource supplies using JualanRSS, an online marketplace that sells in-game resources.
The malicious packages have been found to exploit a vulnerability in the Baileys WhatsApp open source project, allowing attackers to inject channel IDs into the source code of the packages. This has resulted in three different variants of the malware, each implementing different ways of handling the subscription routine. The variants have been identified as Variant 1, which fetches channel IDs from GitHub at runtime; Variant 2, which embeds channel IDs in its source code in cleartext; and Variant 3, which embeds channel IDs in its source code in encoded and obfuscated form.
The malicious packages have been collectively downloaded 490,000 times, with 116,000 occurrences in the last 30 days. This suggests that the attack is ongoing and that the malicious packages are still being actively distributed. The affected packages include "ourin-baileys", "@nexustechpro/baileys", "@badzz88/baileys", "@ostyado/baileys", "levvleys", "@vanzxy/baileys", "@yudzxml/baileys", "@chatunity/baileys", "@kelvdra/baileys", "neuralwhatsapp", "lilys-baileys", "@fyxzpediaa/baileys", "noxleyss", "alipclutch-baileys", "kurobails", "eliteprotech-baileys", "@xayz/baileys", "chromestaff-baileys", "@sanzoffc/baileys", "@sairidev/baileys-new", "cloud-baileys", "@nyzzpediaa/baileys-new", "ishumdz-bail", "nishiki-bail", "diezyclutch-baileys", "oktz-baileys", "my-auto-follow".
The attack has significant implications for developers who use the Baileys WhatsApp open source project. It is advised that developers check if they have been added to the WhatsApp groups, block them, configure detection rules for blocking the malicious npm Baileys packages, and refrain from using packages that require the personal WhatsApp account to be connected.
The incident highlights the need for greater awareness and vigilance among developers when using open source projects. It also underscores the importance of regular security audits and testing to identify vulnerabilities in software packages. Furthermore, it emphasizes the need for developers to be cautious when installing new packages, especially those that require access to their personal accounts.
In conclusion, the discovery of malicious npm packages that exploit WhatsApp account subscriptions without developer consent is a serious security concern. It highlights the need for greater awareness and vigilance among developers, as well as the importance of regular security audits and testing. Developers are advised to take immediate action to protect their personal accounts and to refrain from using packages that require access to their WhatsApp accounts.
Related Information:
https://www.ethicalhackingnews.com/articles/Malicious-npm-Packages-Exploit-WhatsApp-Account-Subscriptions-Without-Developer-Consent-ehn.shtml
https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
Published: Tue Sep 29 11:16:06 2026 by llama3.2 3B Q4_K_M