Skip to content

101 npm packages abuse Baileys to hijack WhatsApp accounts (PhantomSub)

OX Security found 101 npm packages, ~490,000 downloads, that abuse the Baileys library to silently add developers' WhatsApp accounts to spam channels. Most are still live.

Published 3 min read

OX Security has flagged 101 malicious npm packages — collectively downloaded about 490,000 times, 116,000 of those in the last 30 days — that abuse the open-source Baileys WhatsApp library to add the installing developer's WhatsApp account to spam groups and channels without consent. The campaign, which OX calls PhantomSub, is still active: only 16 packages had been pulled as of September 28, and most remain live on npm.

The OX Security writeup (Nir Zadok, Moshe Siman Tov Bustan, Vitalii Chepurko) is the primary source; The Hacker News and BleepingComputer corroborate the numbers.

What the packages do

Baileys is a legitimate WebSocket-based WhatsApp library used to build bots and automations. The PhantomSub packages wrap or impersonate it, and on use they authenticate the victim's linked WhatsApp session and silently subscribe that account to attacker-controlled channels — inflating follower counts for channels that resell TikTok and Mobile Legends accounts. OX groups the packages into three variants by how they fetch their target channel IDs:

  • 19 packages pull channel IDs from GitHub at runtime.
  • 60 packages embed the channel IDs in cleartext.
  • 14 packages use encoded or obfuscated IDs.

Representative package names from the report:

ourin-baileys
@nexustechpro/baileys
levvleys
neuralwhatsapp
noxleyss
cloud-baileys
my-auto-follow

OX ties the subscriptions to Indonesian-run channels including Neural (798 followers), MONTE – BMG (1,000), CORTANA TECH (1,300), and Fyxzpedia.ID – Utama (4,800).

Why it matters

This is account abuse, not a straightforward credential stealer — but the mechanism is the same trust failure. A developer who installs one of these to script WhatsApp automation hands over a live, linked session, and the package uses it. The reputational and account-integrity damage (unexpected channel memberships, possible WhatsApp bans for spam behavior) lands on the victim. Anything built on an unlinked-then-relinked WhatsApp session is exposed.

Action checklist

  1. Audit your dependency tree for Baileys wrappers and forks. Trust the upstream @whiskeysockets/baileys only, and pin it.
  2. If you installed any package from the list above, open WhatsApp → Linked Devices, revoke unknown sessions, and review your channel/group memberships for anything you didn't join.
  3. Block the named channels and add detection rules for packages that require your personal WhatsApp credentials at install or first run.
  4. In CI, deny postinstall network calls to GitHub-hosted config for packages that have no business fetching remote IDs.

Context

PhantomSub is the latest in a run of Baileys-abusing npm campaigns — SafeDep, OSV, and Xygeni flagged earlier waves in August and September 2026 — and part of a broader pattern of npm being used as a distribution channel for account-abuse tooling, not just data theft. We've tracked the same registry-as-malware-vector story in the 14-package vpmdhaj typosquat campaign and the Mastra / easy-day.js supply-chain takeover. The lesson repeats: a package that asks for a live session or credential at install time is the payload.

Related stories