A hundred npm packages quietly conscript WhatsApp bots for spam

OX Security says 101 packages abuse a WhatsApp library to sign victims' bot sessions up for groups they never chose.

CSBadmin
1 Min Read

Researchers have tied 101 npm packages to a scheme that drags developers’ WhatsApp accounts into groups they never asked to join.

OX Security, which named the campaign PhantomSub, says the packages abuse Baileys, an open-source WhatsApp library. When a developer runs one, the code quietly subscribes their authenticated bot session to groups and channels controlled by the publisher. Analysts Nir Zadok, Moshe Siman Tov Bustan and Vitalii Chepurko detailed three variants: 19 packages fetch channel IDs from GitHub at runtime, 60 embed them in cleartext, and 14 hide them in encoded form.

The set has been downloaded about 490,000 times, including 116,000 in the past month. Most destinations are small Indonesian channels that sell bot scripts, in-game resources and social-media boosting, where follower counts act as social proof.

Earlier findings from SafeDep and Xygeni flagged related Baileys forks doing much the same. The through-line, OX notes, is shared infrastructure: many packages point at the same channel IDs and GitHub accounts.

Developers should check whether their account joined strange groups, remove the packages, and steer clear of any library that needs a personal WhatsApp session to run.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.