101 npm Packages Are Quietly Adding Devs to WhatsApp Groups

·
Listen to this article~4 min
101 npm Packages Are Quietly Adding Devs to WhatsApp Groups

Researchers found 101 npm packages quietly adding developers to WhatsApp groups using the Baileys library. Here's how PhantomSub works and why it matters.

### The PhantomSub Campaign: What Actually Happened Picture this: you install a package to save yourself an hour of coding, and somewhere in the background, your WhatsApp account is being used to drag you into group chats you never signed up for. That's not a hypothetical. That's PhantomSub. Cybersecurity researchers have flagged a cluster of 101 npm packages tied to a WhatsApp group subscriber campaign. The packages quietly exploit "Baileys," an open-source WhatsApp library, to add victims to groups without their consent. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," said OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko in a technical writeup. ### Why 101 Packages Is a Bigger Deal Than It Sounds One bad package is annoying. A hundred and one is a supply chain problem. Here's why this pattern keeps working: - Developers rarely audit every dependency, especially small utility packages. - npm's open ecosystem makes publishing trivial, so throwaway packages blend right in. - The attack doesn't need your password. It just needs your session. - By the time you notice the random group invites, the campaign has already done its job. > "The scariest malware isn't the one that crashes your machine. It's the one that borrows your identity and says nothing." That's the whole trick here. Nothing screams. Nothing breaks. You just wake up in a group chat full of strangers. ### How Baileys Gets Turned Against You Baileys is a legitimate tool. Developers use it to build WhatsApp integrations, bots, and automations. It's powerful, well-documented, and free. That's exactly what makes it attractive to attackers. When a malicious package bundles Baileys with hidden logic, it can authenticate as you, join groups on your behalf, and push you into a subscriber funnel. You didn't click anything suspicious. You didn't hand over a code. The package did it all in the background. ### What This Means for Antidetect Browser Users If you're running multiple accounts through an antidetect browser, this story should hit close to home. You already know that identity isolation matters. The same principle applies to your dev environment. A compromised npm package doesn't care about your browser fingerprint. It lives inside your project, your terminal, and your session tokens. Fingerprint spoofing won't save you from a rogue dependency. Only careful dependency hygiene will. ### A Quick Reality Check The researchers didn't just find one sketchy package. They found a coordinated cluster. That suggests whoever's behind PhantomSub treated this like a business, not a prank. So here's the takeaway: treat your npm installs the way you'd treat a stranger asking for your house keys. Politely, but with serious questions. Audit your dependencies, pin your versions, and keep an eye on what your tools are actually doing when you're not looking.