Find notable cyber news and cases, enriched with sources, timelines, and signals.

PhantomSub Baileys-abusing npm package activity

Malware Activity
First reported
Last updated
Happening score
H score 21
1 unique sources, 1 articles

Summary

Hide ▲

The discovery of 101 malicious npm packages abusing Baileys has exposed developers to unwanted WhatsApp group and channel subscriptions across a package set downloaded 490,000 times. Some variants fetch channel IDs from GitHub, while others hide them in cleartext or obfuscated code. The activity turns authenticated WhatsApp sessions into a distribution channel for bot-seller and market groups, many of them tied to Indonesia.

Related Happenings

PhantomSub npm WhatsApp subscriber campaign targeting developers

Campaign
H score32 First: 29.09.2026 16:45 Last: 29.09.2026 16:45 Sources 1

How related: Many packages in this campaign are not independent. The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers.

About this happening: The PhantomSub campaign uses 101 npm packages to add developers to attacker-controlled WhatsApp groups and channels without consent. The packages have drawn 490,...

Indexed-btree npm runtime malware activity

Malware Activity
H score21 First: 20.09.2026 17:11 Last: 20.09.2026 17:11 Sources 1

About this happening: indexed-btree is a malicious npm package that mimics sorted-btree and hides its loader in runtime application code through BTree.prototype.set(), letting a nor...

Shai-Hulud credential-stealing npm worm spreading through poisoned package releases

Malware Activity
H score38 First: 04.08.2026 16:30 Last: 04.08.2026 16:30 Sources 1

About this happening: A Shai-Hulud-based npm supply-chain malware activity spread through poisoned package releases beginning on August 4, 2026, after a maintainer’s GitHub account...

Latest development: 05.08.2026 13:00

Security researchers say the ChainDrop Shai-Hulud-based campaign has already compromised more than 430 npm packages with a combined two billion monthly installs, including packages associated with Deliveroo, Ornikar, OneReach, Picsart, and Qlik.

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The PolinRider campaign now spans Go-based malware distributed through HashiCorp Registry via two Go Modules and two Terraform providers, alongside related m...

Npm v12 default-blocks install scripts, Git dependencies, and remote URLs

Security Tool/Service
H score11 First: 12.06.2026 16:00 Last: 12.06.2026 16:00 Sources 1

About this happening: npm v12 is pushing package installation toward explicit opt-in by default, with install scripts, Git dependencies, and remote URLs blocked unless approved. Sec...

Timeline

  1. 29.09.2026 16:45 2 articles · 3h ago

    101 npm packages abuse Baileys to add developers to WhatsApp groups

    Initial Disclosure

    Researchers identified a cluster of 101 npm packages in the PhantomSub campaign that abuse the Baileys WhatsApp open source project to add developers to WhatsApp groups without consent. The package set was collectively downloaded 490,000 times, including 116,000 downloads in the last 30 days, and the analysis identified three variants: one that fetches channel IDs from GitHub at runtime, one that embeds channel IDs in cleartext, and one that stores them in encoded and obfuscated form.

    Show sources