PhantomSub npm WhatsApp subscriber campaign targeting developers
Campaign
Summary
Hide ▲
Show ▼
The PhantomSub campaign uses 101 npm packages to add developers to attacker-controlled WhatsApp groups and channels without consent. The packages have drawn 490,000 downloads, including 116,000 in the last 30 days, widening the reach of the operation. Shared channel IDs, remote channel lists, and GitHub accounts tie the packages together instead of isolated publisher activity. The campaign runs through Baileys-based package variants that fetch channel IDs from GitHub, embed them in cleartext, or hide them with encoding/obfuscation.
Related Happenings
PhantomSub Baileys-abusing npm package activity
Malware Activity
H score21
First: 29.09.2026 16:45
Last: 29.09.2026 16:45
Sources 1
How related:
The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent,
About this happening:
The discovery of 101 malicious npm packages abusing Baileys has exposed developers to unwanted WhatsApp group and channel subscriptions across a package set downloaded...
PhantomSub Baileys-abusing npm package activity
Malware ActivityHow related: The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent,
About this happening: The discovery of 101 malicious npm packages abusing Baileys has exposed developers to unwanted WhatsApp group and channel subscriptions across a package set downloaded...
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The PolinRider campaign now spans Go-based malware distributed through HashiCorp Registry via two Go Modules and two Terraform providers, alongside related m...
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The PolinRider campaign now spans Go-based malware distributed through HashiCorp Registry via two Go Modules and two Terraform providers, alongside related m...
Mini Shai-Hulud / Miasma / Hades multi-ecosystem supply-chain malware activity
Malware Activity
H score36
First: 26.06.2026 14:05
Last: 26.06.2026 14:05
Sources 1
About this happening:
The Mini Shai-Hulud / Miasma / Hades malware activity added malicious npm releases, GitHub Actions workflow abuse, and a related Go module compromise, increasing t...
Mini Shai-Hulud / Miasma / Hades multi-ecosystem supply-chain malware activity
Malware ActivityAbout this happening: The Mini Shai-Hulud / Miasma / Hades malware activity added malicious npm releases, GitHub Actions workflow abuse, and a related Go module compromise, increasing t...
Miasma supply-chain malware activity
Malware Activity
H score34
First: 10.06.2026 23:27
Last: 10.06.2026 23:27
Sources 1
About this happening:
The Miasma malware activity is enabling supply-chain compromise by stealing build environment and cloud credentials, then using them to poison legitimate packages...
Miasma supply-chain malware activity
Malware ActivityAbout this happening: The Miasma malware activity is enabling supply-chain compromise by stealing build environment and cloud credentials, then using them to poison legitimate packages...
JINX-0164 cryptocurrency recruitment-lure campaign
Campaign
H score39
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
JINX-0164 cryptocurrency recruitment-lure campaign
CampaignAbout this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
Timeline
-
29.09.2026 16:45 2 articles · 3h ago
PhantomSub npm WhatsApp subscriber campaign targeting developers
Initial DisclosureIn August 2026, researchers first found Baileys-based npm forks that silently subscribed installers to attacker-controlled WhatsApp groups. That early phase established the subscription routine later seen across a much larger package set.
Show sources
- 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent — thehackernews.com — 29.09.2026 16:45
- 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent — thehackernews.com — 29.09.2026 16:45