OX Security researchers uncovered 101 malicious npm packages designed to hijack developer WhatsApp accounts and enroll them in unauthorized group chats without permission. The campaign, tracked as PhantomSub, exploits the Baileys open source WhatsApp library to execute the attacks at scale across the JavaScript development community.
The malicious packages weaponize Baileys, a reverse-engineered WhatsApp client library, to programmatically add compromised developer accounts to attacker-controlled group chats. Researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko identified the cluster and documented how the attack chain operates. Developers who installed these packages unknowingly granted remote actors access to their WhatsApp sessions, enabling account takeover and group enrollment operations.
This attack represents a supply chain threat targeting npm, the dominant JavaScript package registry. The npm ecosystem hosts over 2 million packages and processes billions of downloads monthly, making it a high-value target for threat actors. By injecting malicious code into seemingly legitimate packages, attackers bypass traditional security controls and reach thousands of developers through dependency chains. Victims may install compromised packages directly or inherit them transitively through legitimate project dependencies.
The PhantomSub campaign adds developers to WhatsApp groups, likely to build subscriber lists for spam, phishing, or further social engineering attacks. Bulk addition to messaging groups also enables threat actors to distribute malware, conduct credential harvesting, or launch targeted attacks against development teams and organizations. The non-consensual group enrollment creates harassment vectors and exposes developers to scams or malicious content at scale.
OX Security did not disclose the specific names of the 101 packages in initial reporting, but npm likely moved to remove them from the registry upon discovery. Developers should audit their project dependencies immediately, particularly packages installed within recent months. Tools like npm audit and Snyk can flag known malicious packages. Dependency lock files (package-lock.json or yarn.lock) should be reviewed to identify when suspicious packages entered the supply chain.
This incident reflects broader supply chain vulnerabilities in open source software. Attackers exploit the trust developers place in community-contributed code. Previous npm campaigns included the polyfill attack in 2023, which injected malicious JavaScript into websites through widely-used packages, and the UAParser.js compromise in 2021, which distributed password-stealing malware. Each incident demonstrates that package repositories require stronger vetting mechanisms and that developers must implement dependency scanning in their build pipelines.
Organizations should enforce policies requiring code review before dependency updates, implement Software Composition Analysis (SCA) tools to detect known vulnerabilities and malicious packages, and monitor unusual account activity on developer machines. Developers should enable two-factor authentication on npm accounts and WhatsApp profiles to reduce account compromise risk. Restricting npm package installation to approved internal mirrors adds another layer of control.
The PhantomSub campaign highlights the asymmetric risk in modern development workflows. A single malicious package can propagate through thousands of projects before detection. npm's open contribution model, while enabling innovation, creates entry points for supply chain attacks. Fixing this requires both platform-level improvements like enhanced vetting and developer-level discipline through dependency scanning and principle of least privilege access.
