Find notable cyber news and cases, enriched with sources, timelines, and signals.

PhantomSub npm WhatsApp subscriber campaign targeting developers

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The PhantomSub campaign uses 101 npm packages to add developers to attacker-controlled WhatsApp groups and channels without consent. The packages have drawn 490,000 downloads, including 116,000 in the last 30 days, widening the reach of the operation. Shared channel IDs, remote channel lists, and GitHub accounts tie the packages together instead of isolated publisher activity. The campaign runs through Baileys-based package variants that fetch channel IDs from GitHub, embed them in cleartext, or hide them with encoding/obfuscation.

Related Happenings

PhantomSub Baileys-abusing npm package activity

Malware Activity
H score21 First: 29.09.2026 16:45 Last: 29.09.2026 16:45 Sources 1

How related: The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent,

About this happening: The discovery of 101 malicious npm packages abusing Baileys has exposed developers to unwanted WhatsApp group and channel subscriptions across a package set downloaded...

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The PolinRider campaign now spans Go-based malware distributed through HashiCorp Registry via two Go Modules and two Terraform providers, alongside related m...

Mini Shai-Hulud / Miasma / Hades multi-ecosystem supply-chain malware activity

Malware Activity
H score36 First: 26.06.2026 14:05 Last: 26.06.2026 14:05 Sources 1

About this happening: The Mini Shai-Hulud / Miasma / Hades malware activity added malicious npm releases, GitHub Actions workflow abuse, and a related Go module compromise, increasing t...

Miasma supply-chain malware activity

Malware Activity
H score34 First: 10.06.2026 23:27 Last: 10.06.2026 23:27 Sources 1

About this happening: The Miasma malware activity is enabling supply-chain compromise by stealing build environment and cloud credentials, then using them to poison legitimate packages...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

Timeline

  1. 29.09.2026 16:45 2 articles · 3h ago

    PhantomSub npm WhatsApp subscriber campaign targeting developers

    Initial Disclosure

    In August 2026, researchers first found Baileys-based npm forks that silently subscribed installers to attacker-controlled WhatsApp groups. That early phase established the subscription routine later seen across a much larger package set.

    Show sources