$ techbeacon▋
Threats

Researchers Uncover 101 Malicious npm Packages Hijacking Developers’ WhatsApp Accounts

Researchers Uncover 101 Malicious npm Packages Hijacking Developers’ WhatsApp Accounts

A joint analysis by cybersecurity experts has revealed a coordinated campaign that leverages more than a hundred npm modules to surreptitiously add software developers to WhatsApp groups without their knowledge.

The packages, identified as a cluster of 101 distinct modules, exploit the open‑source "Baileys" library – a popular Node.js client for WhatsApp – to automate group enrollment. Once a developer installs any of the compromised modules, the code triggers the Baileys API to subscribe the user’s phone number to a campaign known as "PhantomSub."

PhantomSub functions as a subscriber drive, funneling unwitting participants into large, often spam‑filled WhatsApp groups. Because the addition occurs programmatically, victims typically receive a group invitation notification without any visible prompt or consent, raising concerns about privacy and the potential for further phishing or social engineering attacks.

The discovery underscores the growing risk posed by supply‑chain vulnerabilities in the JavaScript ecosystem. npm, the default package manager for Node.js, hosts millions of modules, many of which are maintained by small teams or individual contributors. Malicious actors can publish seemingly benign libraries that depend on popular tools like Baileys, piggybacking on the trust developers place in established open‑source projects.

Security researchers highlighted that the malicious modules share similar code patterns and publishing timestamps, suggesting a coordinated effort rather than isolated incidents. While the exact origin of the campaign remains unclear, the pattern mirrors previous npm‑based attacks that have injected cryptominers, credential stealers, and adware into development workflows.

In response, the maintainers of Baileys have issued a public advisory urging users to verify the provenance of any package that imports their library and to scrutinize dependency trees for unexpected entries. Developers are also advised to employ tools such as npm audit, lockfile verification, and runtime monitoring to detect anomalous network calls that could indicate unauthorized WhatsApp activity.

The broader community is watching the fallout, as the incident adds pressure on npm to strengthen vetting processes and on open‑source maintainers to adopt stricter contribution guidelines. As supply‑chain attacks become more sophisticated, the episode serves as a reminder that even well‑intentioned utilities can be weaponized, and that continuous vigilance remains essential for software security.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related